Hello,
After upgrading FortiGate to version 7.6.5, we encountered issues with IPsec tunnels. According to the Fortinet technical article, the default Diffie-Hellman group values were changed from 5 to 14, 20, and 21.
Current situation:
Problem: The FortiClient VPN application on Android does not have the option to select DH groups higher than 14. As a result, mobile users cannot establish VPN connection after the FortiGate upgrade.
Questions:
Thank you in advance for your help.
Hi Oktaw
Which FCT version number are you using on your Android? Is it the free version or the licensed one?
14 is still safe. Just configure your Android to use 14 and it should work since they both share at least one common proposal.
It is also possible to use different IPsec config for Windows and Android. Each connects to its dedicated tunnel.
DH14 is supported on 7.6.5, I found some documents for Android, hope they are helpful for you.
1. https://docs.fortinet.com/document/forticlient/7.4.0/android-administration-guide/567000/ike-paramet...
2. https://docs.fortinet.com/document/forticlient/6.0.0/android-user-guide/834699/creating-an-ipsec-vpn...
| User | Count |
|---|---|
| 2869 | |
| 1446 | |
| 835 | |
| 820 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.