We have multiple users experiencing issues with random SSL VPN disconnects. We've tried various versions of the FortiClient from 7.2.x and 7.4.x. No changes regardless of version we try.
All computers are the same Lenovo hardware and are running Windows 11 23H2.
The commonality between users is that all of them have Comcast modems. If a user has his/her own modem and router, no reported issues.
We've tried various uninstalling/reinstalling, reimaging the PCs, nothing works.
Found users with similar issues in the Comcast forums:
I am fairly certain this is an ISP modem issue. However, I am wondering if there is anything we can do to resolve this issue. Setting change, etc.
Thanks for the help.
Please open a tac case and share your ticket number in a direct message to me.
We need access to a Xfinity modem admin web UI for further investigation of the issue.
This issue is probably related to WiFi 6/E and all bands having the same SSID. Windows or Mac switch between different WiFi frequencies in the background and it causes issues with VPN or Streaming apps.
I suggest using separate SSID names for each WiFi band and testing it for a couple of days.
so instead of one SSID for 2.4, 5 and 6Ghz you will have 3 different SSID.
Another test would be to use the Xfinity modem in Bridge mode and connect it to a dedicated AP. The XB8 will be just a MODEM and the AP will handle WiFi, dhcp and nat.
This KB can be helpful in general: https://community.fortinet.com/t5/FortiClient/Troubleshooting-Tip-Bulletproofing-SSL-and-IPsec-Dial-...
We have no access to employees' home modems. Also, the model of the model of the "problem modem" is XB7. XB7 is WiFi 6.
Same concept applies. Create separate SSID for each WiFi band and connect directly to just a specific band. If the modem web console does not have such a setting, disable 2.4Ghz or 5Ghz band completely and test.
This can also be done on OS side if the WIFI driver allows. The change on OS could be very limited in terms of 802.11 a/b/g/n/ac/ax settings.
This command helps with checking the current endpoint WIFI connectivity status: netsh wlan show interfaces
Thanks. Is there anything we can do from the "Fortinet-side" of things?
Perhaps this can help: Bulletproofing SSL and IPsec Dial-Up VPN ... - Fortinet Community
User | Count |
---|---|
2087 | |
1182 | |
770 | |
451 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.