Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pdwoods
New Contributor II

Forticlient VPN 7.4.x "timed out while connecting to ..." IPSec VPN

So for whatever reason on new devices that we have set up the past couple of months we cannot seem to connect to our VPN at all on these new devices. However, the older devices seemingly have no issue.  We have tried reinstalling the C++ libraries, reinstalling FortiClient, and updating the NIC driver but have had no luck. 

 

All of these new devices are running Windows 11 Pro 24H2 and its a mix of 2 Dell Latitude laptops and one Microsoft Surface Pro 9 if that helps with anything.  Also tried looking for some of the older versions on the support page but we don't have the firewall tied to our account so it doesn't let us search through the download page.  I have tried version 5.4.3.0870 of FortiClient that we had saved but that didn't work either although I am not sure if that version is Windows 11 compatible or not. 

 

Not sure where to go from here any help is appreciated!

1 Solution
pdwoods

Here is what the configuration looks like in FCT I am not sure if some default settings got changed in a recent FCT update or if there were changes made to our FGT but usually in the past we could just keep the defaults and not worry about anything besides the gateway and key.

The changes I made are the items circled in red:

1.png

 

2.png

 3.png

View solution in original post

10 REPLIES 10
AEK
SuperUser
SuperUser

When you say FCT VPN 7.4.x, do you mean you also tried 7.4.3?

AEK
AEK
pdwoods
New Contributor II

Correct we’ve tried 7.4.3, 7.4.2 (installed about a month ago) and 5.4.3 (installer we had saved)

ToyinOgunnusiNigeria
New Contributor

Good Day,

 

I am experiencing same problem, my device Fortinet 80E, I can't connect new laptop/desktop to my VPN and device EOL is 2026,  kindly assist. 

pdwoods
New Contributor II

Found a solution that worked for us:

 

So I took a look at the VPN configuration from another machine that is working and turns out in the extra setting at the bottom there were a few differences

 

In Phase 1:

DH Group was set 20 when it should have been set to 5

 

In Phase 2:

Under the second box of Authentication it was using SHA256 instead of SHA1

and

DH Group was set to 20 instead of 5

 

Hopefully this helps anyone in the future wandering through threads for a solution. 

 

Also if anyone could inform me why those settings made the difference in solving this I'd love to learn why.

dingjerry_FTNT

Hi @pdwoods ,

 

The FCT VPN settings have to match the VPN settings on FGT.

 

So how did you configure the VPN settings on FCT?

Regards,

Jerry
pdwoods

Here is what the configuration looks like in FCT I am not sure if some default settings got changed in a recent FCT update or if there were changes made to our FGT but usually in the past we could just keep the defaults and not worry about anything besides the gateway and key.

The changes I made are the items circled in red:

1.png

 

2.png

 3.png

dingjerry_FTNT

Understood.  My suggestion:  Do not rely on the default settings. Always double check the settings to match the VPN configuration on FGT

Regards,

Jerry
ToyinOgunnusiNigeria

This is very helpful, thank you! 

test261

This solution works right away on Windows 10. Thanks for your help and posting the solution. If you're running Windows 11 and it doesn't work, you'll need to install the files from this link first: https://learn.microsoft.com/en-us/answers/questions/4167106/dll-files-missing-after-windows-11-update?forum=windows-all&referrer=answers
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors