Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
peter-supply
New Contributor II

Random FortiClient SSL VPN disconnects for remote users using Comcast Modems

We have multiple users experiencing issues with random SSL VPN disconnects.  We've tried various versions of the FortiClient from 7.2.x and 7.4.x.  No changes regardless of version we try.

 

All computers are the same Lenovo hardware and are running Windows 11 23H2.

 

The commonality between users is that all of them have Comcast modems.  If a user has his/her own modem and router, no reported issues.

 

We've tried various uninstalling/reinstalling, reimaging the PCs, nothing works.

 

Found users with similar issues in the Comcast forums:

https://forums.xfinity.com/conversations/your-home-network/same-issue-vpn-disconnects-from-wifi-on-w....

 

I am fairly certain this is an ISP modem issue.  However, I am wondering if there is anything we can do to resolve this issue.  Setting change, etc.

 

Thanks for the help.

6 REPLIES 6
MZBZ
Staff
Staff

Please open a tac case and share your ticket number in a direct message to me.

M. B.
MZBZ
Staff
Staff

We need access to a Xfinity modem admin web UI for further investigation of the issue.

This issue is probably related to WiFi 6/E and all bands having the same SSID. Windows or Mac switch between different WiFi frequencies in the background and it causes issues with VPN or Streaming apps.

I suggest using separate SSID names for each WiFi band and testing it for a couple of days.

so instead of one SSID for 2.4, 5 and 6Ghz you will have 3 different SSID. 

Another test would be to use the Xfinity modem in Bridge mode and connect it to a dedicated AP. The XB8 will be just a MODEM and the AP will handle WiFi, dhcp and nat.

This KB can be helpful in general: https://community.fortinet.com/t5/FortiClient/Troubleshooting-Tip-Bulletproofing-SSL-and-IPsec-Dial-...

 

M. B.
peter-supply
New Contributor II

We have no access to employees' home modems.  Also, the model of the model of the "problem modem" is XB7.  XB7 is WiFi 6.

MZBZ
Staff
Staff

Same concept applies. Create separate SSID for each WiFi band and connect directly to just a specific band. If the modem web console does not have such a setting, disable 2.4Ghz or 5Ghz band completely and test.

This can also be done on OS side if the WIFI driver allows. The change on OS could be very limited in terms of 802.11 a/b/g/n/ac/ax settings.

This command helps with checking the current endpoint WIFI connectivity status: netsh wlan show interfaces

 

M. B.
peter-supply
New Contributor II

Thanks.  Is there anything we can do from the "Fortinet-side" of things?

MZBZ
Staff
Staff
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors