Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
Contributor III

FortiToken Error with IPSec, SSL VPN works fine???

Hello,

 

since we cant use SSL VPN with the G model we are trying to move to remote IPSec.

We are testing first with the IT department. Last week, everything was fine, no problems connecting to IPSec.

But yesterday one of our technician was not able to connect. The problem was the Token, while connecting he was asked to put the token and he got denied. He tried like 2 times and than switched to SSL VPN where the Token was working the first time connecting.

 

That makes us really uncomfortable thinking about switching all users to IPSec which we have to do some time soon.

I checked the Log files and I dont get an idea about the failure. First it seems OK:
Action negotiate
Status success
Result XAUTH authentication successful

An than the last Log is: Action delete_phase1_sa

The thing is that there is no failure with FortiToken since it works fine with SSL VPN so I dont know where to look for a possible failure.

Thanks!

5 REPLIES 5
AEK
SuperUser
SuperUser

Hi Roland

Are you using FortiAuthenticator or the user/token is directly on FGT?

But anyway first thing I suggest to do is to disable token authentication for the user and try again, just to see if the issue is actually caused by the 2FA or not.

AEK
AEK
RolandBaumgaertner72

Hi,

 

we use FortiToken one time password on the FG. Again, we changed from FG80E to FG90G before sommer and we have like 50 users connecting with SSL VPN + Token all the time. Knowing that WE HAVE TO switch to IPSec we tried with the IT department and first week it was OK, 2 people connected and everything seemed fine. Than the next week suddenly they could not connect entering the FortiToken and since they than switched to SSL VPN with the same Token I have to assume that the Token is not the problem.

 

My problem is that I dont know what to check, look and that with the newt FortiOS we will loose SSL VPN feature and IPSec HAS to work fine.

 

Thanks!

AEK

Hi Roland

The issue is not necessarily in token itself, but can be in the XAuth authentication process, that's why I asked to test IPsec without token. This is part of troubleshooting.

AEK
AEK
funkylicious
SuperUser
SuperUser

hi,

by any chance using IPsec with IKEv1 and FortiClient 7.4.4 ? 

if so, https://community.fortinet.com/t5/FortiGate/Technical-Tip-Dial-Up-IPSec-RA-Authentication-using-Fort... 

"jack of all trades, master of none"
"jack of all trades, master of none"
RolandBaumgaertner72

Hi,

 

we have 7.4.7 and since it is the last one with SSL VPN functionality we cant upgrade to 7.4.9.

 

Last week it worked fine so it is really strange since I am not confident that it works as the SSL VPN and if this error is an issue and we cant upgrade we would have kind of a problem.

 

Any suggestions?

 

Thanks!

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors