Hi Folks,
i've deployed 3 ipsec dialup vpn tunnels and i'm facing the same issue for each one of them.
The 1st time of the day you try to connect via forticlient, insert credential and receive the mfa push notification, the connection always fails, at the 2nd try instead, it works; and this happens for all my tunnels.
Is there any particular configuration to be investigated?
Fortigate version is 7.4.7 and forticlient 7.4.0.1658.
I looked for some technical tips workaround but nothing was found.
Is someone else facing the same issue?
Thank you
Regards
Hi Maerre
Does it happen when you disable token (just for testing)?
Doe it happen with client 7.4.3?
You can also use this command sequence to troubleshoot this case.
diagnose vpn ike log filter ...
diagnose debug console timestamp enable
diagnose debug app authd 60
diagnose debug app fnbamd -1
diagnose debug app ike -1
diagnose debug enable
Hope it helps.
Hi @AEK ,
ran this debugs but nothing helpful, i also searched for some technical tip post but nothing found.
It still doesn't work and the 1st attempt and i've no ideas how to fix it.
Hi Maerre
Try run the above debug commands, collects the output when it fails, and collect the output when it succeed, then compare.. there must be a difference.
This is a bit older post but we experienced the same and there was no "solution" or any info, so I'm just gonna post it here since maybe someone else has the same problem.
We've had the exact same and it turns out for us, this is because of the AlwaysOn Device Tunnel from Microsoft. The first time the FortiClient fails it results in disconnecting the device tunnel. After the devicetunnel is down we can connect with the FortiClient.
If the devicetunnel reconnects faster than we connect with the FortiClient, the process repeats.
Good find. Thanks for sharing, Bongo.
But I wonder which kind of conflict between the two tunnels is causing this.
It's my same error and haven't found a solution yet, also did debug we the connection is correct and when is failing without finding any talking error.
What do you mean with "AlwaysOn Device Tunnel from Microsoft"?
In my scenario i have the forticlient deployment and the cisco duo as Mfa in order to connect, furthermore, i did the same deploy with another customer with forticlient EMS and works correctly, but with the free version of forticlient i can't even open a case and i don't have the fix to this issue.
User | Count |
---|---|
2561 | |
1357 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.