Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HaykCS
New Contributor

IPsec split-tunnel works on Windows FortiClient, but "Protocol timeout" on Android FortiClient

Hello,

I've run into a strange issue with a remote access IPsec VPN on my FortiGate

My Setup:

I used the IPsec VPN Wizard and selected the "FortiClient" template (the one that says it's for Windows, Mac OS, and Android).

The tunnel uses IKEv2, a Pre-shared Key.

My goal is a split-tunnel (only local traffic goes through the VPN).

My Configuration:

IPv4 split tunnel is ENABLED in the tunnel settings, and it points to an address group containing my two local subnets.

The Phase 2 selector is the default one created by the wizard:

I have two firewall policies to allow VPN traffic to my two local networks (one with NAT OFF, one with NAT ON, as my network requires).

The Problem:

Windows (FortiClient VPN app): Works PERFECTLY. It connects, gets an IP, and the split-tunnel works as expected. I can access local resources.

Android (FortiClient VPN app): Fails every time. I use the exact same server IP, PSK, and user credentials. It tries to connect and then fails with the error: "Error: Protocol timeout reached".

What I've Checked:

It's not my phone's network, because my Windows laptop on the same Wi-Fi connects instantly.

It's not my interface, or Windows wouldn't connect either.

My Question: Why does the FortiClient app on Android fail with a timeout, while the FortiClient app on Windows connects perfectly to the exact same tunnel?

I thought the "FortiClient" template and the IPv4 split tunnel setting were supposed to work for both clients. Am I missing a specific setting that the Android FortiClient app needs?

Thank you!

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Hayk

  • Try find VPN logs on the Android and see if you find some relevant information
  • Run traffic sniffer and ike debug on the remote FGT and share the output
  • Even if they share the same WiFi, can you check if your Windows has IPv4 address while your Android has IPv6 address (or dual IPv4-IPv6 addresses)?
AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors