Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
4kusnik
New Contributor

Fortigate-VM64 - No WUI access after installation on ESXi

Hi guys, 

 

I've deployed Fortigate-VM64 (ESXi version) in trial mode. 

I've configured local port2 with set allowaccess http https ping fgfm.

It is replying for ping requests, however, I'm unable to access Foritgate-VM64 via web browser. 

 

In Google Chrome I get: 

"This site can’t provide a secure connection 192.168.100.254 uses an unsupported protocol. ERR_SSL_VERSION_OR_CIPHER_MISMATCH Unsupported protocol The client and server don't support a common SSL protocol version or cipher suite."

 

In Mozilla Firefox I get:

"Secure Connection Failed

An error occurred during a connection to 192.168.100.254. Cannot communicate securely with peer: no common encryption algorithm(s). Error code: SSL_ERROR_NO_CYPHER_OVERLAP     The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.     Please contact the website owners to inform them of this problem."   Please advise if there is something that is missing in initial configuration for web access.   Regards 
4 REPLIES 4
4kusnik
New Contributor

Guys,

 

Any thoughts? 

 

I don't believe I'm the only one who have came across this issue.

rdumitrescu
New Contributor III

Hi, on the free trial you cannot use strong crypto alghoritms. In order to use web gui you should enable only http
Radu_sec

I also encountered the same problem using the trial 2 week license in EVE-NG. I went over my head to try to fix this, by changing configuration parameters on the Fortigate and trying the same in different browsers. In the end, I wound up connecting via HTTP to the GUI. If what rdumitrescu is saying is correct, I am just frustrated that I've wasted so much time on this, but relieved that I finally have confirmation that it doesn't work.

 

 

Br, Radu 

Rosten
New Contributor

I spent HOURS on this topic
Worked like a charm the minute I changed to http

Labels
Top Kudoed Authors