Sigh.
 
 OK, I downgraded to MR6 patch 3. All settings are as I posted previously. Now I can get a stable SSL VPN tunnel, and I can even log in with my LDAP username. But other than that it ain' t working.
 
 None of the tests work. E.g. test for reachability gives me " 192.168.0.250 is not reachable because of permission denied" . And ping from the command line times out. Of course I can' t connect to any internal resources. And I can' t even connect to any site anywhere, because I can' t turn on split tunneling in the Fortigate!! Any attempt to do so results in " destination address of split tunneling policy is invalid" . I' ve tried leaving the destination address range blank, I' ve tried filling in our internal network, and I' ve tried filling in the SSL VPN IP range (192.168.32.1-192.168.32.255). What other range is possible???
 
 Boy, if Fortinet made an IPSec VPN client that worked under Vista, I' d give up on this SSL business.
 
 An up-to-date IPCONFIG:
 
 Windows IP Configuration
 
    Host Name . . . . . . . . . . . . : JON
    Primary Dns Suffix  . . . . . . . : BioProcessConsultants.local
    Node Type . . . . . . . . . . . . : Broadcast
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No
    DNS Suffix Search List. . . . . . : BioProcessConsultants.local
                                        BPTC-Guest
 
 PPP adapter fortissl:
 
    Connection-specific DNS Suffix  . : 
    Description . . . . . . . . . . . : fortissl
    Physical Address. . . . . . . . . : 
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes
    IPv4 Address. . . . . . . . . . . : 192.168.32.1(Preferred) 
    Subnet Mask . . . . . . . . . . . : 255.255.255.255
    Default Gateway . . . . . . . . . : 0.0.0.0
    DNS Servers . . . . . . . . . . . : 192.168.0.250
                                        192.168.0.250
    Primary WINS Server . . . . . . . : 192.168.0.250
    Secondary WINS Server . . . . . . : 192.168.0.250
    NetBIOS over Tcpip. . . . . . . . : Enabled
 
 Ethernet adapter Local Area Connection:
 
    Connection-specific DNS Suffix  . : BPTC-Guest
    Description . . . . . . . . . . . : Realtek RTL8101E Family PCI-E Fast Ethernet NIC (NDIS 6.0)
    Physical Address. . . . . . . . . : 00-1B-38-4B-CB-D0
    DHCP Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes
    Link-local IPv6 Address . . . . . : fe80::916:e53f:6e62:c5e8%7(Preferred) 
    IPv4 Address. . . . . . . . . . . : 192.168.16.66(Preferred) 
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Lease Obtained. . . . . . . . . . : Saturday, October 25, 2008 9:43:49 AM
    Lease Expires . . . . . . . . . . : Sunday, October 26, 2008 9:43:48 AM
    Default Gateway . . . . . . . . . : 192.168.16.1
    DHCP Server . . . . . . . . . . . : 192.168.16.1
    DHCPv6 IAID . . . . . . . . . . . : 184556344
    DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-10-31-35-C8-00-1B-38-4B-CB-D0
    DNS Servers . . . . . . . . . . . : 192.168.16.1
    NetBIOS over Tcpip. . . . . . . . : Enabled