I have been struggling with forticlient on Opensuse Tumbleweed. It worked fine until last week but now, after a zypper dup, (I did others before and there were no issues) I can't establish the connection anymore. Even trying boot across previous system snapshot, it doesn't work. I use a SAML integrated VPN and it authenticates successfully just before the client dropping the connection. Can anyone help me to fix this?
20241203 16:50:09.950 TZ=-0300 [sslvpn:INFO] main:1817 Init
20241203 16:50:09.951 TZ=-0300 [sslvpn:INFO] main:622 Load profile: BLN
20241203 16:50:09.952 TZ=-0300 [sslvpn:DEBG] main:631 Inherit local DNS: No
20241203 16:50:09.952 TZ=-0300 [sslvpn:DEBG] main:644 DNS service resetting interval: 0
20241203 16:50:09.952 TZ=-0300 [sslvpn:INFO] main:329 Get DBUS session bus address
20241203 16:50:09.954 TZ=-0300 [sslvpn:DEBG] main:333 Failed to find DBUS session bus address in dbus-daemon, try to find in dbus-broker
20241203 16:50:09.955 TZ=-0300 [sslvpn:DEBG] main:393 get passwd: true, get cert passwd: false, get user input: false
20241203 16:50:09.961 TZ=-0300 [sslvpn:INFO] main:329 Get DBUS session bus address
20241203 16:50:09.962 TZ=-0300 [sslvpn:DEBG] main:333 Failed to find DBUS session bus address in dbus-daemon, try to find in dbus-broker
20241203 16:50:09.963 TZ=-0300 [sslvpn:INFO] main:1288 Load profile: BLN
20241203 16:50:09.963 TZ=-0300 [sslvpn:DEBG] main:1676 FCT UID: F473F21C23864864B1FED27271AA89F6
20241203 16:50:09.964 TZ=-0300 [sslvpn:DEBG] main:1691 EMS not registed
20241203 16:50:09.964 TZ=-0300 [sslvpn:DEBG] main:1704 Public IP is not set
20241203 16:50:09.964 TZ=-0300 [sslvpn:INFO] main:1481 State: Connecting
20241203 16:50:09.979 TZ=-0300 [sslvpn:DEBG] vpn_connection:1506 Server URL: https://vpn.[omitted]:10443
20241203 16:50:09.986 TZ=-0300 [sslvpn:INFO] main:1481 State: Logging in
20241203 16:50:09.986 TZ=-0300 [sslvpn:INFO] sslvpn:92 ApiEncMethod: 0
20241203 16:50:09.986 TZ=-0300 [sslvpn:INFO] sslvpn:93 ApiRemoteAuthTimeout: 120
20241203 16:50:09.986 TZ=-0300 [sslvpn:INFO] sslvpn:94 ApiServerSalt: 127ac17e
20241203 16:50:09.986 TZ=-0300 [sslvpn:INFO] sslvpn:95 flag: 1247
20241203 16:50:09.986 TZ=-0300 [sslvpn:INFO] vpn_connection:1944 /remote/saml/login
20241203 16:50:13.254 TZ=-0300 [sslvpn:DEBG] vpn_connection:406 https server 'vpn.[omitted]' has this certificate, which looks good to me:
/CN=[omitted]
20241203 16:50:13.444 TZ=-0300 [sslvpn:DEBG] vpn_connection:599 http connection closed.
20241203 16:50:13.445 TZ=-0300 [sslvpn:DEBG] vpn_connection:478 Response line: 200 OK
20241203 16:50:13.445 TZ=-0300 [sslvpn:INFO] sslvpn:234 Authentication passed.
20241203 16:50:13.445 TZ=-0300 [sslvpn:INFO] vpn_connection:1944 /remote/fortisslvpn
20241203 16:50:16.676 TZ=-0300 [sslvpn:DEBG] vpn_connection:595 http request error: 1
20241203 16:50:16.676 TZ=-0300 [sslvpn:EROR] vpn_connection:552 socket error = Resource temporarily unavailable (11)
20241203 16:50:16.676 TZ=-0300 [sslvpn:EROR] vpn_connection:1815 Error: Can not connect to VPN server.
20241203 16:50:16.686 TZ=-0300 [sslvpn:DEBG] vpn_util:260 Get connection name: Wired connection 1
20241203 16:50:16.687 TZ=-0300 [sslvpn:DEBG] dns:210 Read DNS backup /etc/nm_resolv.forticlient.backup:
20241203 16:50:16.687 TZ=-0300 [sslvpn:DEBG] dns:213 JSON parse error, content dump:
20241203 16:50:16.694 TZ=-0300 [sslvpn:DEBG] vpn_util:260 List fctvpn connection: Wired connection 1
lo
enp2s0
20241203 16:50:16.694 TZ=-0300 [sslvpn:DEBG] dns:632 default interface restore: 1, vpn interface restore: 1
20241203 16:50:16.694 TZ=-0300 [sslvpn:DEBG] mtu:116 Restore MTU.
20241203 16:50:16.694 TZ=-0300 [sslvpn:DEBG] mtu:120 No MTU backup file was found. Skip.
20241203 16:50:16.694 TZ=-0300 [sslvpn:DEBG] route:160 clean up route...
20241203 16:50:16.694 TZ=-0300 [sslvpn:DEBG] route:164 Cleanup file not found
20241203 16:50:16.694 TZ=-0300 [sslvpn:DEBG] main:1911 exception: Error: Can not connect to VPN server.
20241203 16:50:16.775 TZ=-0300 [sslvpn:INFO] main:1817 Init
20241203 16:50:16.775 TZ=-0300 [sslvpn:INFO] main:1829 VPN is running in restore DNS mode
20241203 16:50:16.787 TZ=-0300 [sslvpn:DEBG] vpn_util:260 Get connection name: Wired connection 1
20241203 16:50:16.788 TZ=-0300 [sslvpn:DEBG] dns:210 Read DNS backup /etc/nm_resolv.forticlient.backup:
20241203 16:50:16.788 TZ=-0300 [sslvpn:DEBG] dns:213 JSON parse error, content dump:
20241203 16:50:16.799 TZ=-0300 [sslvpn:DEBG] vpn_util:260 List fctvpn connection: Wired connection 1
lo
enp2s0
20241203 16:50:16.800 TZ=-0300 [sslvpn:DEBG] dns:632 default interface restore: 1, vpn interface restore: 1
20241203 16:50:16.800 TZ=-0300 [sslvpn:DEBG] mtu:116 Restore MTU.
20241203 16:50:16.800 TZ=-0300 [sslvpn:DEBG] mtu:120 No MTU backup file was found. Skip.
Hi,
What is the fortios and FCT version
What error you are getting in FGT VPN event logs
Created on 12-04-2024 08:16 AM Edited on 12-04-2024 10:11 AM
Hello Joshi!
Forticlient version: 7.4.0.1636
FortiOS 7.0.15
In the following imagens you can see the server side logs.
The "FGT VPN event logs" you asked, do you mean the sslvpn.log I posted above? If not, please tell me which source log file would you like: sslvpn.log, main.log, fctsched.log or confighandler.log
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1748 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.