Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mark8263
New Contributor III

Issues with 'free' ipsec vpn

Anybody else having issues with getting the 'free' ipsec client to work?

I've been messing around with this for a couple of weeks and so far, with 5 different machines and 4 different clients - only 1 machine will connect.

I've already engaged support but since this is the 'free' client - they have exhausted all that they can help with.

I don't need all the 'add-on' stuff with the vpn, just need it to connect - stay stable and provide some basic routing (thru it).

What happens is that i install, configure, connect - and it hangs.  nothing until the connection drops off a few minutes later. packet captures seem to indicate that 'all' the tcp packets aren't getting sent/received and therefor phase 1 never completed.

 

10 REPLIES 10
funkylicious
SuperUser
SuperUser

what FCT versions have you tested and what version worked ?

what OS does those system have ?

"jack of all trades, master of none"
"jack of all trades, master of none"
mark8263

all builds up to 7.4.3 hotfix 1.8758

machines have been 5 different win 11 machines and 1 server. only works on a server - no workstation flavors

funkylicious

i would recommend testing w/ 7.4.1 if you can or something in the 7.2.X version

"jack of all trades, master of none"
"jack of all trades, master of none"
mark8263

Same issue - client times out. 

thanks for the suggestion tho..

 

funkylicious

if the ipsec settings are correct i would try deleting the current ipsec profile and re-create it from scratch or export it from a working computer and import it into another.

debugging at the remote end shows anything upon connecting?

"jack of all trades, master of none"
"jack of all trades, master of none"
mark8263

No - nothing which helps.

funkylicious

have had this issue plenty of times.

make sure that DH groups are not set to multiple ones but to a single one.

also, trust me when i say this cuz it drove me crazy at times w/o a real explination. try removing/deleting the VPN profile and make it from scratch ( make sure that you are running the latest visual c++ redis )


give this also a try
https://community.fortinet.com/t5/FortiClient/Troubleshooting-Tip-FortiClient-IPSEC-VPN-connection-i... 

"jack of all trades, master of none"
"jack of all trades, master of none"
mark8263

I've checked the DH groups and both sides are set to 20 so I don't think that's the issue. In regards to removing/deleting and adding the vpn client back I think I've tried this process with 5 different vpn clients now and even configured the dialup vpn client to connect to either of my wan address w/o issues.  even tried ipsec2 instead of ipsec 1 as i'd seen some mention in 1 of the fortigate documentation about the 'newer' clients utilizing/preferring ipsec2 over 1.

 

vpolovnikov
Staff & Editor
Staff & Editor

There are some IPsec troubleshooting commands in the FortiOS documentation with log examples that may help to some extent: i.e. https://docs.fortinet.com/document/fortigate/7.6.5/administration-guide/044240/ipsec-related-diagnos...

VP
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors