Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jason-Ace
New Contributor

Forticlient Woes in IPSEC Mode

Since SSLVPN will be going away on small units, I have been switching users to IPSEC VPN as we roll out new firewalls. However, I have been having a lot of trouble with the VPN-only Forticlient.

 

The big issue is that, for 30-40% of new Forticlient installs, the client does not seem to respond to the firewall's replies in Phase 1. Firewall log shows P1 successful, then timed out 30 seconds later. If I run wireshark on the client, I see the firewall's traffic arrive at the PC, but then the Forticlient seems to just re-send the first packet again. Seems like only an uninstall-reboot-reinstall has a chance to fix this, winsock reset doesn't seem to do anything.

The other thing is that when the client fails to connect, the window never updates, it just sits there on "disconnecting." Closing the window and re-opening it from the taskbar gets it back to normal, but I don't remember SSLVPN's ever acting like that.

 

Today I tried using the Windows native client instead, but it seems like there's no way to make it work in IKEv2 mode with PSK, it seems like it could work with certificates but not with just PSK. 

 

Am I missing something on any of these issue? Thanks!!!

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
AcumenIT
New Contributor

I don't have any helpful information to share at this time but also struggling with the IPSec configs. Some users can connect; some cannot. Mac users seem to be able to connect but PC cannot. I will be following this thread. 

btan
Staff & Editor
Staff & Editor

Hi Jason-Ace,


I am thinking whether enabling IKE_fragmentation would help in your case.
Refer:

https://docs.fortinet.com/document/forticlient/7.4.3/xml-reference-guide/629016/ike-fragmentation-ex...


Also, page58 and 59 in:
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/a67f40a2-9d13-11ed-8e6d-fa163e...

 

If you are using VPN-only FortiClient, <enable_ike_fragmentation> is XML-only configuration. You might have to export the XML, edit it, and then re-import it in order to set <enable_ike_fragmentation>1.

Regards,
Bon
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors