I have got FortiClient to connect to my enterprise VPN, but I can not connect through my router. The error message is: VPN has "trouble connecting with the remote gateway, retrying now..." The connection through a mobile phone net is successful. Are there any settings, I should do on the router?
Thanks
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I'd expect SPI would need to be enabled for the ALG settings to work. If you're still having problems I'd do two things next.
1, Take a look at the VPN logs on the FortiGate that's terminating the VPN as that often gives a pointer.
2, run a Diag sniff packet any 'host x.x.x.x' on the Fortigate (replace the x.x.x.x with the public IP of the D-Link). You should see the IPSec phase 1 traffic (UDP 500/4500) then the actual encrypted payload (phase 2 - protocol 50). If you don't see protocol 50 arriving on the FG then the D-Link is dropping it.
You normally need to enable IPSec support on routers. Have you enabled IPSec ALG (page 85 in the manual).
I'd expect SPI would need to be enabled for the ALG settings to work. If you're still having problems I'd do two things next.
1, Take a look at the VPN logs on the FortiGate that's terminating the VPN as that often gives a pointer.
2, run a Diag sniff packet any 'host x.x.x.x' on the Fortigate (replace the x.x.x.x with the public IP of the D-Link). You should see the IPSec phase 1 traffic (UDP 500/4500) then the actual encrypted payload (phase 2 - protocol 50). If you don't see protocol 50 arriving on the FG then the D-Link is dropping it.
Dear Steve,
I actually cannot reach the VPN IT guys. Have You any suggestion, what should I do, what should I set in configuration, if the D-Link GO-RT-AC750 router drops IPSec UDP packets?
Sandor MUNK
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1720 | |
1095 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.