I'm facing issues while trying to set up FortiClient VPN on KUbuntu 22.04. The installation goes smoothly after manually adding a dependency package. However, when I attempt to connect using Single Sign On (SSO), the authentication window briefly opens and closes, leaving me stuck on the "Connecting..." stage. This is the window where I should enter my username and password and then use a 2FA app for verification.
Even after enabling "Use external browser as user-agent for saml user authentication," the problem persists. The same behavior occurs, and an external browser doesn't open as expected.
I had no trouble with this kind of connection on Kubuntu 20.04. Has anyone managed to successfully establish this type of connection on (K)Ubuntu 22.04?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
I'm no Linux geek. After searching/testing I managed to get connected on a Kubuntu 22.04 LTS clean installation with FortiClient Ver. 7.2.1 and/or 7.2.2
Prereq was a installation of the gnome-shell:
$sudo apt update && sudo apt ugrade
$sudo apt install gnome-shell
But after this there are several redundant app installed on the system, coming from the gnome shell installation.
To reduce this I would be happy if a tech from Fortinet would find out whats missing on Kubuntu LTS 22.04 with KDE Plasma 5.24.7 or higher and no Gnome
Kind regards
Norbert
Hi,
To understand the issue better, can you provide me more information about the issue:
1) Are the windows user able to connect:
2) What is the FortiClient version ?
3) have you tried a different version of FortiClient:
4) Are you trying to use IPsec or SSL:
5)Attach error screenshot
Best Regards,
Abhimanyu
Created on 08-07-2023 05:52 AM Edited on 08-07-2023 05:58 AM
1) Yes
2) 7.0.7.0246
3) I also tried 7.0.0.0018
4) I am not sure
5) There is no error message. Instead, the login window briefly pops up and disappears and then it gets stuck in "Connecting..."
Hello @Vlid
Could you please provide below SSL VPN debug output:
diag debug reset
diagnose vpn ssl debug-filter src-addr4 x.x.x.x>>>User Public IP
diag debug appl sslvpn -1
diag debug enable
Post running the above command, please connect to SSL VPN and share the logs which got generated.
Thanks
Shaleni
Where should I enter this? The Linux command line does not recognize the "diag" command
Hello @Vlid
Please run the above commands in FortiGate CLI and Post running the above command, please connect to SSL VPN and share the logs which got generated.
Thanks
Shaleni
I am using the FortiClient VPN GUI, I can't find any CLI within it. Could you please guide me on how to access the CLI?
Hi @Vlid
We have not observed issues regarding this (K)Ubuntu 22.04 version.
In your Linux machine please try to reinstall the SSL VPN and then restablish the SSL VPN using the SAML SSO.
https://docs.fortinet.com/document/forticlient/7.2.1/linux-release-notes/213138
Regards
Priyanka
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
I tried this version, but it still has the same issue. I set up a virtual machine with Xubuntu 20.04, and I can connect without any issues inside it. At this point, I'm seriously considering giving up and reverting my system back to 20.04.
Hi @Vlid
In this case, you can collect the below command output and raise a TAC case to investigate further.
could you kindly collect and share the following data:
-SSL VPN config (FGT CLI > conf vpn ssl settings)
-FortiClient XML conf (EMS GUI > Endpoint Policies & Components > Manage policies > edit assigned policy > Download XML config.)
-FortiClient debug logs after replication:
1) EMS GUI > Endpoint Profile > System Settings > select assigned profile> use Advanced view instead of Basic > Log Level > change "info" to "debug" > select all features
2) Wait for FCT to sync the profile
3) Reproduce the issue
4) FCT GUI > Settings > export logs
-Finally, if you can provide command line outputs:
before VPN connection try:-
$cat /etc/resolv.conf
$resolvectl status
$ifconfig
$dig toyourinternalresource.com
after VPN connection try:-
$cat /etc/resolv.conf
$resolvectl status
$ifconfig
$dig toyourinternalresource.com
Regards
Priyanka
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1522 | |
1020 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.