I have seen a few posts with the same title but nobody seems to have found a solution yet. Has anyone found a working solution to the issue where FortiClient will connect to VPN then immediately disconnect? We are using FortiClient with EMS, and if the user has auto retry checked it will repeatedly try to reconnect and fail. Sometimes I can force it to start working again by shutting down the Forticlient app and restarting the computer but I can't find any useful information in logs or debug info. FG is on 7.4.2, FC client is 7.2.3, and EMS 7.2.2 (which I plan to update to 7.2.4 sometime this week). If you have any solutions I appreciate it!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
@rlewcosa
Can you please check if there is any other software installed on your machine that might conflict with FortiClient? Some other VPN solution?
I can confirm there is no other VPN software, we had previously been using the free Forticlient before upgrading to the full ZTNA version with EMS/FortiAuth. This is occurring however on both devices that had been upgraded and new, fresh Windows installs.
Do you see it successfully establish (screen changes, gives you an IP), or does it stop at a specific percentage (98%)? Are you using SAML?
In cases like these, I like to disable IPv6 on both your physical Ethernet adaptor, and the Fortinet SSLVPN adaptor as well.
Created on 03-11-2024 10:45 AM Edited on 03-11-2024 10:46 AM
It does successfully establish - User will hit connect, it reaches 48% and prompts for their token key which they enter, then pauses for a second at 98%. After that it will say connected successfully followed immediately by a disconnected message. When it does that they usually are not successful trying to connect again, they have to shutdown the client and reboot. I'll try disabling the IPv6 and see what happens.
I am wondering if latency could be causing it? The devices are laptops in police cars running almost 100% off of cellular. While we generally have good reception and average around 50mbps off LTE, I'm wondering if any bit of latency causes issues with the connection process. I do have an email out with our account rep so if I find out anything useful I'll update the thread.
**Edit: I should add, when viewing the authentication logs in FortiAuthenticator for the affected user, it will show multiple "login successful, awaiting token" and "token successful" entries back to back, no error messages or failures.
Hmmm, I would also try with and without DTLS if you know latency is gonna be high. I have had similar cases where DTLS would refuse to work, and others where it would only work with DTLS on.
I'll try that and see what happens. DTLS is currently off but I'll enable it and listen for any end users having problems.
Any updates on this? We are having similar issues with some clients connecting to SSL VPN.
Are you the same user as seen previously on this thread? If not, a good place to start would be to look at the other suggestions and report the results back.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.