Hi All,
The VPN getting stuck at 98% and below is the errors i see in the client logs. we tried to re-install the forticlient software but no luck.
5/16/2024 11:49:57 AM warning sslvpn CSslvpnAgent::InitPipeHandle() 137 CreateFile() failed.. LastError=231
5/16/2024 11:49:57 AM error sslvpn Failed to connect to SslvpnDaemon, LastError=0
5/16/2024 11:49:57 AM error sslvpn CSslvpnAgent::Initialize() 178 InitPipeHandle() failed.
5/16/2024 11:50:15 AM error sslvpn failed to create tunnel_thread thread
5/16/2024 11:50:15 AM error sslvpn error: ras_loop(), waitResult=1.
5/16/2024 11:50:15 AM error sslvpn failed to create ras_thread thread
5/16/2024 11:50:15 AM error sslvpn failed to create monitor_thread thread
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @Mohammed_H ,
Do you use a free FortiClient version?
This may also occur when attempting to negotiate SSL VPN with the free version of FortiClient.
The below might help:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Possible-reasons-for-FortiClient-SSL...
https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-fails-at-98/ta-p/248363
https://community.fortinet.com/t5/Support-Forum/VPN-stuck-at-status-98/td-p/75229
Best regards,
@fricci_FTNT yes we use free version. I dont see problem with other user who is also using free version.
Hi @Mohammed_H ,
Please download FCremove.exe in order to uninstall FortiClient:
Please run FCremove tool in a safemode.
1. Download FCRemove.exe tool from the support website (Support > Firmware Download > FortiClient > Download > Select the version > click on HTTPS next to the FortiClientTools)
2. Unzip the file and locate the FCRemove.exe tool under Utils folder
3. Put the tool somewhere within the file system (Desktop, temp, etc)
4. Boot the machine in the Safe Mode:
- open Run command prompt and enter msconfig
- click on the Boot tab and check the Safe Boot box
- hit Ok and restart the machine
5. When booted into the Safe mode, open the Windows command line as Administrator
6. Run FCRemove.exe
7. When FortiClient gets deleted, repeat the steps outlined in step 4 but this time uncheck the Safe Mode box
8. Reboot the machine
Best regards,
I have tried fcremove.exe earlier in normal mode ( user login ). Let me try run from safe mode and check.
Try reinstalling forticlient ZTNA after getting the fcremove utility.
Run it in safe mode, reboot and install it again.
Did you ever get this resolved? I am trying this on one of the devices and it keeps erroring on me.
Hello,
May I know the Forticlient version that you are using?
Also try to uninstall the Forticlinet and try the same or a different client version.
And please check if IPv6 on the NIC of the client machine, if so disable it.
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-fails-at-98/ta-p/248363
I ended up figuring my issue out as it was not all users it was only 80 percent of the users that were having it. The issue was the remoteauthtimeout.
config system global
set remoteauthtimeout 60
end
After I set this to 60, all the users were able to connect.
Tagging this for reference. I have almost exactly the same in the logs. We are new to Fortigate and aren't impressed so far.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.