Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Michael_Houser
New Contributor

Fortinet FortiClient not connecting

Our Fortigate 200A (v4.0,build0513,120130 (MR3 Patch 5) is set up with VPN. When I try to use the FortiClient (5.2.0.0591) I can connect but I don' t see any packets being received and therefore can' t use Telnet or RDC But when I connect to the web portal using https://xx.xx.xx.211:10443 in a web browser I can ping and telnet using the portal.. I have tried using https://xx.xx.xx.211 , xx.xx.xx.211 and https://xx.xx.xx.211:10443 in the ForitClient but I get the same results.. I am connecting via a Mac OSX 10.7 and also a Window 7 Pro machine It was working but nothing in the network has changed. My users are authenticating via a local username and password on the fortigate.. I am using SSL and not IPSEC Thanks all
11 REPLIES 11
emnoc
Esteemed Contributor III

diag debug flow is your friend you claim nothing is has changed, but it was working? Has fwpolicies been shifted or deleted? Are you using split-tunnel? Has tunnel-mode been checked? What does the client show for traceroutes? etc......but I would start with the diag debug flow and the address of the client if the client has an address. The output of that diagnostic will give your the next course of action to take or follow.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Nihas
New Contributor

Has tunnel-mode been checked?
It might be configured only for web-access. You can check the tunnel-mode part.
Nihas [\b]
Nihas [\b]
Michael_Houser
New Contributor

I have been looking for Web-Access only but can' find it. In VPN-->SSL-->Portal-->SSLTunnel-->Tunnel Mode Name: IP Mode: RangeUser Group IP Pools: SSLVPN_global Split Tunneling: -- Checked-- .. Is this the only place I need to look at? Is " diag debug flow" in the CLI? Thanks for the reply' s
Michael_Houser
New Contributor

I don' t know if this helps or not but using the Web-Portal interface using the " Connection Tool" I can Ping, RDC, Telnet to anything on the LAN but I am unable to do this using the FortiClient..
Nihas
New Contributor

There are three SSL Portal is available in FGT. 1. web only - ( I think you are using this one) , there you will be able to access things like RDP,telnet etc through connection tool. But cannot connect via dedicated client. 2. Tunnel Mode - You will be able to find a connect button on Portal to ( Or you can use a dedicated SSL VPN client as well) launch the native SSL VPN client and you will be able to connect . 3. Full mode - Will provide you both the options together in a portal , either you can access via connection tools, or you can connect the tunnel and access the things. Note:- All these can be customized as any of the types. You have to change the portal type to Full Mode /Tunnel Mode to get the access through client. Is there any way to get an output of the below command? FGT # show vpn ssl settings
Nihas [\b]
Nihas [\b]
Michael_Houser
New Contributor

Here are the settings login as: administrator administrator@10.0.0.247' s password: Cascio $ show vpn ssl settings config vpn ssl settings set dns-server1 10.0.0.231 set dns-server2 192.168.0.33 set tunnel-ip-pools " SSLVPN_global" end " You have to change the portal type to Full Mode /Tunnel Mode to get the access through client. " is this what is considered a " Split Tunnel" or is a Split Tunnel" something different? Thanks
Nihas
New Contributor

Hi Yes, split tunneling is different. Basically Spit tunnel determines whether all your traffic passes through fortigate or through your local gateway. Enable- Traffic will pass through your local gateway Disable - traffic will pass only through your fortigate, and if you need internet access you have to create a policy. Here, you can go to the ssl vpn user group and change portal to tunnel mode.
Nihas [\b]
Nihas [\b]
Michael_Houser
New Contributor

After restarting I can ping the gateway of the Fortigate when connected using the FortiClient. But I stiil cant ping anything else in the LAN 192.168.x or 10.0.0.x .. In the Users-->Usergroup -->usergroup SSL_VPN .. Below is what I have selected
Michael_Houser
New Contributor

Below is how the Tunnel is configured
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors