Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

SSL Negotiation error

Hi there, We have a Fortigate-60 unit which we are using for SSL VPN connections. While trying to Remote Desktop into a server in Web mode, we keep getting the following error: “Connection Exception. SSL negotiation failed, please check your Fortigate configuration”. I have attempted to attach a screenshot, but am getting website errors. How shall we go about resolving this error? Thanks for your time
14 REPLIES 14
abelio
SuperUser
SuperUser

SSL negotiation failed
Can you elaborate the whole scenario a little bit? fortiOS, windows version (basically if you run Vista or not), Iexplorer version, error code, etc

regards




/ Abel

regards / Abel
Not applicable

FortiOS: Where do I find this info? OS: XP Pro IE: 7.0 Error code: None supplied, only " SSL negotiation error"
abelio

FortiOS: Where do I find this info?
Directly from Dashboard or Status page. Or using CLI command " get system status" There' s several comments about IE7 in this forum. I.e: http://support.fortinet.com/forum/tm.asp?m=23623&appid=&p=&mpage=1&key=explorer&language=single&tmode=&smode=&s=#25432 Also check http://kc.forticare.com/default.asp?id=1727&Lang=1&SID= There' re there several situations that could apply to your situation

regards




/ Abel

regards / Abel
Not applicable

Everything installs fine - the SSL VPN client installs perfectly, the web mode Java applet runs fine. I' ve already tried putting the site into Trusted Sites and turning every setting in IE7 down to the lowest possible security level - none of it works.
rwpatterson
Valued Contributor III

Did it work under IE6 or Firefox?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

I don' t actually have a computer with IE6 on it anymore unfortunately, but I tested it in Firefox and there is no difference at all
rwpatterson
Valued Contributor III

Are you sure the correct ports are opened? (RDP source ports 1024-65535, destination 3389-3389)

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

Opened at what point? We can connect to the machine via RDP internally, but there is no RDP pinhole in the router as I was under the impression that the FortiGate used SSL for the connection.
rwpatterson
Valued Contributor III

The FGT uses SSL for connection to the network. It will still only allows the protocols that are enabled in the policy. If the policy does not contain RDP, then you will not be able to use RDP throught the SSL tunnel to communicate through to the server. For a quick test, select the service ' ANY' and see what you get.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors