- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Random FortiClient SSL VPN disconnects for remote users using Comcast Modems
We have multiple users experiencing issues with random SSL VPN disconnects. We've tried various versions of the FortiClient from 7.2.x and 7.4.x. No changes regardless of version we try.
All computers are the same Lenovo hardware and are running Windows 11 23H2.
The commonality between users is that all of them have Comcast modems. If a user has his/her own modem and router, no reported issues.
We've tried various uninstalling/reinstalling, reimaging the PCs, nothing works.
Found users with similar issues in the Comcast forums:
I am fairly certain this is an ISP modem issue. However, I am wondering if there is anything we can do to resolve this issue. Setting change, etc.
Thanks for the help.
- Labels:
-
FortiClient
-
SSL-VPN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please open a tac case and share your ticket number in a direct message to me.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We need access to a Xfinity modem admin web UI for further investigation of the issue.
- Model numbers: CGM4981COM
- Friendly model name: XB8
- https://www.xfinity.com/support/articles/broadband-gateways-userguides
This issue is probably related to WiFi 6/E and all bands having the same SSID. Windows or Mac switch between different WiFi frequencies in the background and it causes issues with VPN or Streaming apps.
I suggest using separate SSID names for each WiFi band and testing it for a couple of days.
so instead of one SSID for 2.4, 5 and 6Ghz you will have 3 different SSID.
Another test would be to use the Xfinity modem in Bridge mode and connect it to a dedicated AP. The XB8 will be just a MODEM and the AP will handle WiFi, dhcp and nat.
This KB can be helpful in general: https://community.fortinet.com/t5/FortiClient/Troubleshooting-Tip-Bulletproofing-SSL-and-IPsec-Dial-...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have no access to employees' home modems. Also, the model of the model of the "problem modem" is XB7. XB7 is WiFi 6.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Same concept applies. Create separate SSID for each WiFi band and connect directly to just a specific band. If the modem web console does not have such a setting, disable 2.4Ghz or 5Ghz band completely and test.
This can also be done on OS side if the WIFI driver allows. The change on OS could be very limited in terms of 802.11 a/b/g/n/ac/ax settings.
This command helps with checking the current endpoint WIFI connectivity status: netsh wlan show interfaces
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks. Is there anything we can do from the "Fortinet-side" of things?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Perhaps this can help: Bulletproofing SSL and IPsec Dial-Up VPN ... - Fortinet Community
