Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JoaquimdeSousa
New Contributor

Fortinet tunnel is showing inactive state

Hello All,

I have this issue. FortiGate 40F (v6.4.15 build2095)

Fortinet tunnel is showing inactive state

Reproduction : I use the GUI not the CLI.

1. I created a vpn user

2. I assigned this user to a vpn group

3. I used th VPN wizard to create an Dialup FortiClient (Windows, Mac OS, Android) :
-> https://docs.fortinet.com/document/fortigate/6.4.15/administration-guide/785501/forticlient-as-dialu...

4. In Firewall & Objects
-> Addresses :
-> Created automatically -> vpn1_range = 192.168.1.1-192.168.1.254
-> Created automatically -> vpn1_split = members = lan
-> Firewall Policy :
-> Created automatically -> vpn_vpn1_remote_0

-> The VPN was created, but shows INACTIVE.

I really don't understand. Can some help, please ?

Kind Regards,
Jo

1.jpg

12 REPLIES 12
dingjerry_FTNT

Hi @JoaquimdeSousa ,

 

You have to make sure that the FortiClient settings match the settings on FortiGate.

 

If it still does not work, you have to run the IKE debug commands.

Regards,

Jerry
JoaquimdeSousa
New Contributor

here is a better image : https://ibb.co/64t3c4z

dingjerry_FTNT

Hi @JoaquimdeSousa ,

 

Thanks. Some settings on FCT do not match the settings on FGT. Such as: 

 

Proposals in Phase1 and Phase2;

DH group in Phase2;

 

You have to make sure that the address range in phase1 is not part of your internal network which you want to allow FCT clients to access.

 

So it's still better to run the IKE debug commands to collect outputs for further troubleshooting.

Regards,

Jerry
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors