Hi,
after upgrading Fortigate 200D from 5.4 to 6.0.3 we have an issue in SSL VPN with fortitoken.
here is the case :
our client uses Forticlient 6.0.1.0099
we defined username with local password, and attached serial number of fortitoken in each username.
when we connect with forticlient, after input the required token, we got error :
Unable to logon to the server. Your login credentials not be configured properly (-12)
we tried to change the password with alphanumeric but the result same.
when we revoke the fortitoken from associated username and relogin, the vpn connected.
here is the debug :
[82:VPN:2de]req: /remote/fortisslvpn [82:VPN:2de]rmt_web_auth_info_parser_common:439 no session id in auth info [82:VPN:2de]rmt_web_access_check:682 access failed, uri=[/remote/fortisslvpn],ret=4103, [82:VPN:2de]req: /remote/login [82:VPN:2de]rmt_web_auth_info_parser_common:439 no session id in auth info [82:VPN:2de]rmt_web_get_access_cache:756 invalid cache, ret=4103 [82:VPN:2dd]sslvpn_read_request_common,682, ret=-1 error=-1, sconn=0x2a9a672800. [82:VPN:2dd]Destroy sconn 0x2a9a672800, connSize=1. (VPN) [82:VPN:2df]allocSSLConn:280 sconn 0x2a9a672800 (6:VPN) [82:VPN:2df]SSL state:before SSL initialization () [82:VPN:2df]SSL state:before SSL initialization () [82:VPN:2df]SSL state:SSLv3/TLS read client hello () [82:VPN:2df]SSL state:SSLv3/TLS write server hello () [82:VPN:2df]SSL state:SSLv3/TLS write change cipher spec () [82:VPN:2df]SSL state:SSLv3/TLS write finished () [82:VPN:2df]SSL state:SSLv3/TLS write finished:system lib() [82:VPN:2df]SSL state:SSLv3/TLS write finished () [82:VPN:2df]SSL state:SSLv3/TLS read change cipher spec () [82:VPN:2df]SSL state:SSLv3/TLS read finished () [82:VPN:2df]SSL state:SSL negotiation finished successfully () [82:VPN:2df]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 [82:VPN:2df]req: /FortiClientSslvpnClearCacheUrl/for/Wini [82:VPN:2df]def: (nil) /FortiClientSslvpnClearCacheUrl/for/WininetLibrary/1/2/3/4/5/6/7/8/9/0/a/b/c/d/e/f/g/h/i/j/k/l/m/n/o/p/q/r/s/t [82:VPN:2de]Timeout for connection 0x2a9a559400.
[82:VPN:2de]Destroy sconn 0x2a9a559400, connSize=1. (VPN) [82:VPN:2df]Timeout for connection 0x2a9a672800.
please help, thanks!!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I have the same issue, FortiGate FortiOS 6.0.5 and Forticlient 6.0.4 when Forticlient is installed on windows server 2016 or 2019
there is no option on ssl vpn settings to enable sslv3
on windows server 2019 the client is trying to connect using tlsv1.3 (this option is not available on fortiOS 6.0.5)
I am not sure if works on FortiOS 6.2 (I have to plan the upgrade)
thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1696 | |
1091 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.