Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bryanzim
New Contributor

SSL VPN Hangs at 98% Windows Server 2012 R2

I am utilizing the latest FortiClient (5.1.28.540) with only the SSL VPN install. I am unable to establish an SSL VPN connection with this OS as it hangs at 98%. The Fortinet unit is a Fortigate 60D with 5.0.6 firmware. This problem is particular to Server 2012 R2 as Server 2012 was successfully connecting before the OS upgrade. There seems to be something different in the networking functionality of Server 2012 R2 vs Windows 8.1 which needs to be accounted for. I have also tried the latest SSL_VPN, FortiClient SSL-VPN V4.4.2294, as well as FortiClient V5.0.7.0333. I am the administrator on the computer and the program is running as administrator.
4 REPLIES 4
AtiT
Valued Contributor

Hi, Just some info - maybe it will help. A month ago we upgraded our cluster on customer site and during the upgrade he updated his Windows server. After the update the LDAP was OK but FSSO connection stopped working. The problem was in the firewall of the Windows server - the rules for the ports 8000, etc... were missing. After the creation of the policies it was working again. Check the firewall on the server.

AtiT

AtiT
bryanzim
New Contributor

Sorry I had forgot to mention that I had tried firewall disabled already which would have successfully connected if it was a fire wall issue. Here are some FortiClient log snippets which show some interesting issues: 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: connecting SSL ... 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: call back called! 1/13/2014 10:10:27 AM Debug VPN (repeated 1 times in last 0 sec) FortiSslvpn: 5596: call back called! 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: SSL connected 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: [DoXmlConfig]... 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: info: SslBlockingWrite(020831C0, 01C67440, 276, 10000) called. 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: [DoXmlConfig]: GET remote/fortisslvpn_xml ... (send 276 of 276 bytes): GET /remote/fortisslvpn_xml HTTP/1.1 Host: sslvpn Cookie: SVPNCOOKIE=9aXATzrfwBYI4EyQLMajpNMJaYJx5IkVVDlbHXc4i26UZRY9BJ8fRqL1EFB0spBp%0awdbkYUPVoUmg2oUWfHgXTjG2UxZXAfJ32jdy2TkYkGpqxTLYcon+CJsiBH0atp7T%0a2SjL9Fw7tNeujHgjdl9lYyKFqsy8UqgLDqiWyKIH98DbPulTuPk/g/j+pAoGR+ut%0a ---- . 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: info: SslBlockingRead(020831C0, 01C65254, 8191, 10000) called. 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: [DoXmlConfig]: GET remote/fortisslvpn_xml ... (received 830 bytes): HTTP/1.1 200 OK Date: Mon, 13 Jan 2014 15:10:27 GMT Set-Cookie: SVPNCOOKIE=9aXATzrfwBYI4EyQLMajpNMJaYJx5IkVVDlbHXc4i26UZRY9BJ8fRqL1EFB0spBp%0awdbkYUPVoUmg2oUWfHgXTjG2UxZXAfJ32jdy2TkYkGpqxTLYcon+CJsiBH0atp7T%0a2SjL9Fw7tNeujHgjdl9lYyKFqsy8UqgLDqiWyKIH98DbPulTuPk/g/j+pAoGR+ut%0a; path=/; secure; httponly Transfer-Encoding: chunked Content-Type: text/xml X-Frame-Options: SAMEORIGIN <?xml version=' 1.0' encoding=' utf- 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: [DoXmlConfig]: Xml= <?xml version=' 1.0' encoding=' utf-8' ?><sslvpn-tunnel ver=' 1' ><fos platform=' FGT60D' major=' 5' minor=' 00' mr_num=' 00' patch=' 5' build=' 0252' branch=' 252' /><client-config save-password=' on' keep-alive=' on' auto-connect=' on' /><ipv4><dns ip=' 10.10.0.50' /><dns ip=' 208.67.222.222' /><split-tunnel-info><addr ip=' 10.10.0.0' mask=' 255.255.255.0' /></split-tunnel-info></ipv4><idle-timeout val=' 300' /><auth-timeout val=' 28800' /></sslvpn-tunnel> ---- 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: [DoXmlConfig]: dnsSuffixes = 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: info: ssl_connect -> Set XmlConfig OK. 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: [DoLicCheck]... 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 1208: info: ras_loop(), XmlConfig OK. 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 1208: RasSetEntryProperties disable default remote gateway 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: info: SslBlockingWrite(020831C0, 01C67440, 770, 10000) called. 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: [DoLicCheck]: GET /remote/licensecheck ... (usr=XXX, send 770 of 770 bytes): GET /remote/licensecheck HTTP/1.1 Host: sslvpn Cookie: SVPNCOOKIE=9aXATzrfwBYI4EyQLMajpNMJaYJx5IkVVDlbHXc4i26UZRY9BJ8fRqL1EFB0spBp%0awdbkYUPVoUmg2oUWfHgXTjG2UxZXAfJ32jdy2TkYkGpqxTLYcon+CJsiBH0atp7T%0a2SjL9Fw7tNeujHgjdl9lYyKFqsy8UqgLDqiWyKIH98DbPulTuPk/g/j+pAoGR+ut%0a FCC_License: 5645523D310A4643545645523D352E312E32382E3534300A5549443D36443230444536424443433234314646424333394132353645433142364636 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: info: SslBlockingRead(020831C0, 01C64418, 8191, 10000) called. 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: [DoLicCheck]: GET /remote/licensecheck ... (received 600 bytes): HTTP/1.1 200 OK Date: Mon, 13 Jan 2014 15:10:27 GMT FCC_Status: 8 FCC_Message: 5645523d310a434f44453d300a Transfer-Encoding: chunked Content-Type: text/html X-Frame-Options: SAMEORIGIN <html> <head> <meta http-equiv=" Content-Type" content=" text/html; charset=utf-8" > <meta http-equiv=" Pragma" content=" no-cache" > <meta http-equiv=" cache-control" content=" no-cache" > <meta http-equiv=" cache-control" content=" must-reva 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: [DoLicCheck]: After DecodeLicenseResult(): s=8, r=0, message= 5645523d310a434f44453d300a VER=1 CODE=0 ---- 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 5596: ===>send to login, ret=310 buf=GET /remote/sslvpn-tunnel?dns0=205.171.3.65&dns1=205.171.2.65 HTTP/1.1 Host: sslvpn Cookie: SVPNCOOKIE=9aXATzrfwBYI4EyQLMajpNMJaYJx5IkVVDlbHXc4i26UZRY9BJ8fRqL1EFB0spBp%0awdbkYUPVoUmg2oUWfHgXTjG2UxZXAfJ32jdy2TkYkGpqxTLYcon+CJsiBH0atp7T%0a2SjL9Fw7tNeujHgjdl9lYyKFqsy8UqgLDqiWyKIH98DbPulTuPk/g/j+pAoGR+ut%0a 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 11348: WdcConfigDnsCacheServiceEnabled(0) called. 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 11348: WdcConfigDnsCacheServiceEnabled(0): WdcsConfig=0 1/13/2014 10:10:28 AM Debug VPN FortiSslvpn: 11348: DnsCacheServiceStartType = 2 1/13/2014 10:10:29 AM Debug VPN FortiSslvpn: 7600: monitor_thread() called 1/13/2014 10:10:29 AM Debug VPN FortiSslvpn: 7600: register_route_change_event_ipv4() called 1/13/2014 10:10:29 AM Debug VPN FortiSslvpn: g_dwKeepRunningFlag = 0. 1/13/2014 10:10:29 AM Debug VPN FortiSslvpn: 12396: no active connection So the SSL Connects successfully but the local client computer is not successfully configured. I believe there are some peculiarities to Server 2012 R2 as a client vs Windows 8.1.
SteveRoadWarrior
New Contributor III

(crosspost) We had a similar problem with a Windows 8.1 client. He had an older version of FortiClient SSL VPN installed and had upgraded. Fix: Uninstall client. Reboot. Reinstall client. In the process we also disabled UAC, but I don' t expect this was the fix. Left UAC at the 2nd to the lowest setting (one notch above the completely disabled setting). Then rebooted.
Jana
New Contributor

Hi guys any update on this. I did all the solution you have mentioned but no use. please help someone. Thanks
Labels
Top Kudoed Authors