Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aymericQA
New Contributor

SSL VPN UP but no traffic - intermittent

Hi,

 

I'm setting VPN SSL tunnel for my salespersons (win10 + 4g network)

I use forticlient to connect, with split tunneling.

The laptop is connected via Wifi to a 4G mobile access point.

The firewall is a FG100D

 

Quite frequently, the connection goes well, tunnel is connected, but no traffic go through.

I have to disconnect the tunnel with forticlient, then reconnect, (sometimes more than once), and finally it's working fine.

 

(I tried to use the SSL VPN GATEWAY, to launch an RDP session, without FORTICLIENT installed, and it seems to work flawlessly in the same condition).

 

Any Idea ?

 

Thanks

Aymeric

3 REPLIES 3
aymericQA
New Contributor

here is what I found so far, when enabling debug log:

 

when the tunnel is working fine:

 

end of the log

 

[234:root:457]Destroy sconn 0x7f93d5188400, connSize=0. (root) lcp_reqci: returning CONFREJ. lcp_reqci: returning CONFACK. lcp_up: with mtu 1354 ipcp: returning Configure-REJ ipcp: returning Configure-NAK ipcp: returning Configure-ACK ipcp: up ppp:0x7f93d4417000 caller:0x7f93d5081000 tun:33 Cannot determine ethernet address for proxy ARP local IP address my.wan.ip.155 remote IP address 10.212.134.200 [235:root:458]ppp_associate_fd_to_ipaddr:634 associate 10.212.134.200 to tun (ssl.root:33) [235:root:457]ap_read_request,554, ret=-1 error=-1, sconn=0x7f93d5188400. [235:root:457]Destroy sconn 0x7f93d5188400, connSize=1. (root)

 

but when not working, there's a timeout (

 

[236:root:448]Destroy sconn 0x7f93d5188400, connSize=0. (root) lcp_reqci: returning CONFREJ. lcp_reqci: returning CONFACK. lcp_up: with mtu 1354 ipcp: returning Configure-REJ ipcp: returning Configure-NAK ipcp: returning Configure-ACK [234:root:454]Timeout for connection 0x7f93d5188400. [234:root:454]Destroy sconn 0x7f93d5188400, connSize=0. (root) [235:root:453]Timeout for connection 0x7f93d5188400. [235:root:453]Destroy sconn 0x7f93d5188400, connSize=1. (root) [235:root:454]sslvpn_send_ctrl_msg:874 0x7f93d5081000 message: heartbeat laptop.ip.55.245 [235:root:454]sslvpn_send_ctrl_msg:874 0x7f93d5081000 message: heartbeat laptop.ip.55.245

 

 

but the VPN is marked as connected !

afrank

Hi,

 

Have you found a solution here ? We have the same phenomena wit FortiOS 6.0.6 + FortiClient 5.6.6 and 6.0.8 too.

 

Cheers,

aymericQA

Hello, it was quite a long time ago ...

We identified the issue as coming from our 4G provider at that time (I guess some issue with NATing inside their network or something like that).

We could have switched to another provider, but we switched to an IPSec tunnel instead.

It made no différence for us ...

 

Hope it helps ...

 

Aymeric

Labels
Top Kudoed Authors