Hello,
I am experiencing a complex issue with SSL VPN connections on iOS devices using FortiClient and FortiClient VPN apps. Below, I detail the problems and the steps I've taken so far. Any guidance or suggestions from the community would be greatly appreciated.
Issue Summary:
Environment:
Best regards,
Hi @hbac
Yes i'm aware of the issue with connecting and DTLS
But my issue is deeper than that.
Even if i apply the workaround and am able to connect i'm not able to use VNC over the connection.
This issue is also on the Forticlient EMS app.
@jhe,
Since you have FortiClient EMS, I would suggest opening a ticket with FortiClient technical support team to troubleshoot the issue.
Regards,
The question may be what exactly on VNC "is not working". Timeout, connection reset, screen coming up, then closing. They all will have different areas to look at.
VNC is a protocol like any other would be, causing traffic from your workstation to another node, the server. On the FortiGate you should capture whether the VNC traffic (tcp/5900 default) when you initiate it, arrives and hits a policy (or not).
A packet capture with sniffer and flow trace debug will help with this:
diag debug console timestamp enable
diag debug flow filter port 5900
diag debug flow show iprope enable
diag debug enable
diag debug flow trace start 20
Created on 11-03-2023 07:00 AM Edited on 11-03-2023 07:02 AM
@Markus_M Thank you for the suggestion. I will further document the issue.
I can confirm that traffic is flowing when saml and dtls are both enabled and i can see packets back and forth the vnc app simply does not connect. And after i have used RVNC no other traffic works either. I have to reconnect.
I'm 99% sure the issue is with the iOS clients.
As i mentioned vnc works perfectly fine with a local user no SAML and DTLS active.
Also works flawlessly with Windows, MacOS and Android with both SAML and DTLS enabled.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.