Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rwdorman
New Contributor III

SSL VPN Client download from non-Java Browsers

This is a move of a sub sub sub thread in another forum... I have a TAC case open on this but i' m digging deeper into this and I' m wondering if some of the guru' s around these parts could help me understand a bit about how this works. These are my assumptions only and i' m looking for any corrections, nots that i wildly don' t get it or input that you may have. In non Java or Bad Java browsers (Chrome on a Mac, unsupported weirdo' s, systems without JVM' s) client attempting to use the web portal, instead of receiving the embedded web page applet interface are offered a link to download the " fat" (mini) SSLVPN only client which they can then use for a " lite" experience. These files are downloaded (proxied?) to the client from the fortigate. the FGT checks its cache for the file name being requested, if it exsists, sends it along, if not, asked Fortiguard, pulls it from there and then offers it to the client The command: fnsysctl ls -l /var/log/package_cache should show all of the packages that the Fortigate has LOCALLY and if there is not something in at directory that matches what the client, through the non Java/fancy method of embedding it, is attempting or has previously attempted to download (cached). Assuming I understand that, i would imaging that clicking on the link within the browser, would result in it attempting to download a file name that matches the one in the GUI, in this example: the browser shows FortiClientInstaller-Mac-Enterprise-5.2.1.dmg. If clicking on that file does not work... we arrive at my issue If that packaged does not appear in the cache show from the CLI command that would suggest a few possibilities to me... here are my guesses A) The file name in the browser is a misnomer and is actually pointing to another file name below B) The file name in the browser results in a URL sent to FortiGuard that no longer exsists C) The attempt to download the given file name from Fortiguard in order to cache fails for $reason Am I understanding this correctly? Is there another possibility? FW-01 # fnsysctl ls -l /var/log/package_cache -rw-r--r-- 1 0 0 Thu May 29 12:21:43 2014 230839 FortiClientMiniSetup-Mac-Enterprise-5.0.9.dmg -rw-r--r-- 1 0 0 Tue Aug 12 16:51:03 2014 307608 FortiClientMiniSetup-Mac-Enterprise-5.2.0.dmg -rw-r--r-- 1 0 0 Fri Sep 12 07:48:59 2014 318950 FortiClientMiniSetup-Mac-Enterprise-5.2.1.dmg -rw-r--r-- 1 0 0 Wed Dec 18 17:36:02 2013 500696 FortiClientMiniSetup-Windows-Enterprise-5.0.7.exe -rw-r--r-- 1 0 0 Tue Aug 12 16:50:54 2014 492136 FortiClientMiniSetup-Windows-Enterprise-5.2.0.exe -rw-r--r-- 1 0 0 Fri Sep 12 07:53:31 2014 484288 FortiClientMiniSetup-Windows-Enterprise-5.2.1.exe -rw-r--r-- 1 0 0 Thu Jul 31 11:28:53 2014 492136 FortiClientMiniSetup-Windows-x64-Enterprise-5.2.0.exe -rw-r--r-- 1 0 0 Fri Sep 12 13:49:25 2014 484288 FortiClientMiniSetup-Windows-x64-Enterprise-5.2.1.exe -rw-r--r-- 1 0 0 Sun Sep 7 19:11:44 2014 1125 sslvpn_version.h -rw-r--r-- 1 0 0 Wed May 14 13:01:25 2014 2906511 sslvpnclient.tar.gz

-rd 2x 200D Clusters 1x 100D

1x 60D FortiOS 5.2 FortiAP 221C FAZ 200D

-rd 2x 200D Clusters 1x 100D 1x 60D FortiOS 5.2 FortiAP 221C FAZ 200D
0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors