Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Oktawiusz
New Contributor

IPsec VPN connection issue on FortiClient Android after FortiGate upgrade to v7.6.5

Hello,

After upgrading FortiGate to version 7.6.5, we encountered issues with IPsec tunnels. According to the Fortinet technical article, the default Diffie-Hellman group values were changed from  5 to 14, 20, and 21.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-IPsec-tunnels-not-connecting-after-upgrade...

 

Current situation:

  • On PC clients, the issue was resolved by changing the configuration and setting matching DH groups (14, 20, 21) on both sides of the connection
  • Tunnels are working correctly after synchronizing the settings

Problem: The FortiClient VPN application on Android does not have the option to select DH groups higher than 14. As a result, mobile users cannot establish VPN connection after the FortiGate upgrade.

Questions:

  1. Is there a planned update for FortiClient Android application with support for DH groups 20 and 21?
  2. What is the recommended temporary workaround - should we roll back the configuration on FortiGate to older DH groups, or is there another option?
  3. Is it possible to configure different IPsec policies for mobile and desktop clients?

Thank you in advance for your help.

2 REPLIES 2
AEK
SuperUser
SuperUser

Hi Oktaw

Which FCT version number are you using on your Android? Is it the free version or the licensed one?

14 is still safe. Just configure your Android to use 14 and it should work since they both share at least one common proposal.

It is also possible to use different IPsec config for Windows and Android. Each connects to its dedicated tunnel.

AEK
AEK
HarryTran
Staff
Staff
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors