Hi
Note: This is not a Fortinet VPN question. It's a FortiOS question.
I have a few employees using a non-Fortinet VPN connection to one of our customers. The connections (setup using Windows 10's built-in VPN settings) work fine outside of our office, but inside our office, connections are never finalized. The software connects, gives login information and then goes back to try connecting again. It never errors out. I have limited access to the machines (and no access to the customer VPN server) and can't test much (or often). I see nothing in the logs that suggest our FortiGate device is filtering access, but the client insists they are not blocking us in any way.
All I need is a point in the right direction. Where in the FortiOS might there be a setting restricting access to external VPNs?
Hi
IPSEC works on 2 UDP protocol No's (UDP 500 or 4500) and Fortigate there is Service called IKE need to allow on inside to outside policy to work VPn from inside .
Just check if they use IPSEC or other protocols .
Regds,
Ashik
Do you have the FortiGate doing Application Control and blocking Proxy? That might be blocking your VPN connections.
Ashik: I know they aren't using PPTP or L2TP. I'm not sure if it's SSTP or IKE though. I'll look into the settings though.
tanr: We have some Application Control, but their IP isn't showing up in the log as being affected (which makes sense). I'll check my proxy settings, but I don't believe it's that either.
Thanks to both of you. Hopefully I'll get a chance it test it again this week.
diag debug flow is your friend here. If yoou set the policy to and service to "any", does it work? What policy are you matching now? Is it IPSEC ?
If yes for IPSEC UDP500/4500 and protocol #50 ( yes protocol not port # for ESP )
Ken
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1751 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.