Hello All,
I have this issue. FortiGate 40F (v6.4.15 build2095)
Fortinet tunnel is showing inactive state
Reproduction : I use the GUI not the CLI.
1. I created a vpn user
2. I assigned this user to a vpn group
3. I used th VPN wizard to create an Dialup FortiClient (Windows, Mac OS, Android) :
-> https://docs.fortinet.com/document/fortigate/6.4.15/administration-guide/785501/forticlient-as-dialu...
4. In Firewall & Objects
-> Addresses :
-> Created automatically -> vpn1_range = 192.168.1.1-192.168.1.254
-> Created automatically -> vpn1_split = members = lan
-> Firewall Policy :
-> Created automatically -> vpn_vpn1_remote_0
-> The VPN was created, but shows INACTIVE.
I really don't understand. Can some help, please ?
Kind Regards,
Jo
Hi @JoaquimdeSousa ,
You have to make sure that the FortiClient settings match the settings on FortiGate.
If it still does not work, you have to run the IKE debug commands.
here is a better image : https://ibb.co/64t3c4z
Hi @JoaquimdeSousa ,
Thanks. Some settings on FCT do not match the settings on FGT. Such as:
Proposals in Phase1 and Phase2;
DH group in Phase2;
You have to make sure that the address range in phase1 is not part of your internal network which you want to allow FCT clients to access.
So it's still better to run the IKE debug commands to collect outputs for further troubleshooting.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1749 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.