Hi,
I'm experimenting a new weird issue with an IPSEC dialup VPN created on a FortiGate 100F with FortiOS 7.6.4. The thing is that I can reach a connection with the FortiClient v7.4.3.1790, and my connection is able to send Bytes but it's not receiving any Bytes. I've been trying several configuration using the IKEv1 and IKEv2, and unfortunately, using IKEv2 is not connecting and using IKEv1 I was able to have a connection but only is sending Bytes and not receiving. Any idea or solution will be are welcome... One more thing, I already reviewed the article ID 352403 posted by Stephen_G, about a similar situation but, my configuration of the FortiClient is the same to the configuration suggested in that article, and it's not working... Please see the snapshots below...
Thank you in advance for all your help...
Solved! Go to Solution.
Better to switch to IKEv2 ASAP. FortiClient 7.4.4+ will not support IKEv1 anymore.
hi,
maybe this https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-IPsec-VPN-is-connected-but-receive... and disabling IPv6
Hi,
Thank you so much for your time to try to help me with this issue, I tried all recommendations that I found in your link, but unfortunately none of them works, and the problem continue...
Hi, you need to change IKE phase 1 and phase 2 proposal, from sha1 to sha256 (both on fortigate and forticlient), so your encryptions will be AES128-AES256-SHA256-SHA256. This will work with IKEv1. On the other hand if you want to use IKEv2 I think the best ideea is to downgrade the firmware back to 7.6.3. Also i recommand to check Auto keep alive from Fortigate (your VPN connection)-> phase 2 selector. I worked 3 days to solve this problem, but is more difficult that I thought, and in the end I did the downgrade back to 7.6.3.
And also, I'm not sure if this really matter, but I used channel 5 and 14 for tests on DH group.
Hi Mariusmuresan,
Thank you so much for sharing your experience with this matter, and I did as you recommended but, unfortunately, the problem persist... I appreciate your help...
Hi @mariusmuresan what is your device ?
Hi @ReneGut ;
I will test your case in my lab with a simple configuration. However it is a big help if you can share the related configuration to my email bhoang@fortinet.com ; Thank you
Bill
Thank you so much Bill, this is a great news... I will send you the information requested asap today or tomorrow...
Hi all,
We have reproduced the similar issue in our lab and are working with the Engineering team to find the root cause. I will update this thread with the status. Thank you.
Bill
User | Count |
---|---|
2570 | |
1364 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.