Since SSLVPN will be going away on small units, I have been switching users to IPSEC VPN as we roll out new firewalls. However, I have been having a lot of trouble with the VPN-only Forticlient.
The big issue is that, for 30-40% of new Forticlient installs, the client does not seem to respond to the firewall's replies in Phase 1. Firewall log shows P1 successful, then timed out 30 seconds later. If I run wireshark on the client, I see the firewall's traffic arrive at the PC, but then the Forticlient seems to just re-send the first packet again. Seems like only an uninstall-reboot-reinstall has a chance to fix this, winsock reset doesn't seem to do anything.
The other thing is that when the client fails to connect, the window never updates, it just sits there on "disconnecting." Closing the window and re-opening it from the taskbar gets it back to normal, but I don't remember SSLVPN's ever acting like that.
Today I tried using the Windows native client instead, but it seems like there's no way to make it work in IKEv2 mode with PSK, it seems like it could work with certificates but not with just PSK.
Am I missing something on any of these issue? Thanks!!!
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
I don't have any helpful information to share at this time but also struggling with the IPSec configs. Some users can connect; some cannot. Mac users seem to be able to connect but PC cannot. I will be following this thread.
Hi Jason-Ace,
I am thinking whether enabling IKE_fragmentation would help in your case.
Refer:
Also, page58 and 59 in:
https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/a67f40a2-9d13-11ed-8e6d-fa163e...
If you are using VPN-only FortiClient, <enable_ike_fragmentation> is XML-only configuration. You might have to export the XML, edit it, and then re-import it in order to set <enable_ike_fragmentation>1.
User | Count |
---|---|
2571 | |
1364 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.