Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ialhusari93
New Contributor II

Fortigate 7.0.17 SSL VPN disconnections and drops

Dears,

Kindly note that we are experiencing SSL VPN disconnections and slowness after we upgrade the frameware to 7.0.17. The issue affects all users, and the only temporary workaround is to restart the firewall.

Unfortunately, after some time, the same issue occurs again. We would appreciate your support in investigating the root cause and providing a permanent solution.

 

Regards,

7 REPLIES 7
GeorgeZhong
Staff & Editor
Staff & Editor

Hi,

Based on the description, it could be due to underlying firmware issue. However, the FortiOS 7.0.17 is old and out of TAC support. It is suggested to upgrade to latest mature version FortiOS 7.4.9 for permanent solution.

 

In current FortiOS 7.0.17, if SSLVPN is slow again, instead of rebooting the FortiGate, we can try to restart the corresponding daemon by below commands as workaround:

 

diagnose sys process pidof sslvpnd   <<<< Check process ID of "sslvpnd" daemon

fnsysctl killall sslvpnd   <<< Kill and restart sslvpnd daemon

 

diagnose sys process pidof sslvpnd   <<<< Check process ID of "sslvpnd" daemon again and confirm it has changed

 

Regards,

George

ialhusari93

Hi George,

Thank you for your response, kindly note I am in HA mode how can I make  sure that both firewalls got sslvpn reset daemon correctly  without reboot 

GeorgeZhong

Hi @ialhusari93 , we only need to reset the daemon on the primary unit since SSLVPN connection is handled by it only while secondary is just standby.

ialhusari93

hi GeorgeZhong,

 I am in active active mode

filiaks1

Shouldn't you want a stable version as 7.0 is not supported ?

 

If you want a quick workaround for process reboot I have documented this :

 

https://community.fortinet.com/t5/Support-Forum/Restart-Fortigate-http-gui-processes-automatically-b...

 

 

The process name is sslvpnd

ialhusari93

Hi filiaks1

 

would you let me know what is the most stable version after 7.0.17 that support ssl vpn ?

 

thank you

karvagear
New Contributor

If someone encounters this and absolutely need a user to connect right away ( and can't roll back) it somehow doesn't read past the first group when a user has several. it will work if the use only has the vpn group in 365 assigned to them.

https://19216811.cam/ https://1921681001.id/
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors