Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mirza_Asad2723
New Contributor II

SSLVPN is not establishing through the primary ISP via FortiClient.

Dear Concern,

 

In the FortiClient application, I have defined 2 remote gateways, but the connection is not being established with the first one, only with the second one. This happens only when I manually replace the first remote gateway with the second one in FortiClient. It used to work with both, but now it suddenly stopped working with the first one for an unknown reason. When I try to connect to the first one, it stays at 0% and doesn't give any error. As soon as I set the second remote gateway as the first one, it connects immediately.

 

Both WAN IPs are responding to ping. In the FortiGate Firewall VPN settings, both WAN interfaces are selected in the listen interface. So, how should I troubleshoot to find out what the issue is and how can I resolve it?

 

Can anyone help me to resolve the issue

15 REPLIES 15
dbhavsar
Staff
Staff

Hello @Mirza_Asad2723 ,

can you please collect following debugs as per this article:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-Troubleshooting/ta-p/189542 and update the thread.

Or have you tried with different FortiClient version?

 

DNB
Mirza_Asad2723
New Contributor II

Dear @dbhavsar ,

 

No, I haven't tried it on a different version of FortiClient. Further let me debug according to your shared link and then will update 

Mirza_Asad2723
New Contributor II

@dbhavsar 

 

After enabling debug mode, when I connect using FortiClient, no data is received from the first remote gateway and the FortiClient status stays on 0%. However, when I replace the first remote gateway with the second remote gateway in the FortiClient application, data starts coming in. 


hbac

Hi @Mirza_Asad2723,

 

No data means traffic is not reaching the FortiGate. It should at least fails at 10%. If it is 0%, I think the issue is on the FortiClient side. Please try deleting and recreating the VPN connection on FortiClient. If it doesn't help, please try a different FortiClient version. 

 

Regards, 

Mirza_Asad2723
New Contributor II

@hbac 

 

Currently my FortiClient version is 7.2.4.0972. According to you, let me try after recreating the VPN connection.

Mirza_Asad2723

@hbac 

 

After recreating the VPN connection, the same issue is occurring. As soon as I click the connect button, it first goes to 10%, then drops to 0%, and stays stuck at 0%.

Shashwati
Staff
Staff

Hello,

 

Please run the following command to capture traffic on Firewall while testing using the First Gateway 

Verify that Firewall is receiving the traffic from user for the First Gateway

diagnose sniffer packet any 'host X.X.X.X'  6 0 l       [Use user public IP address]

Mirza_Asad2723

@Shashwati 

 

When I run this command and enter the IP of the first remote gateway on the host, and then connect using FortiClient after running the command, I get this response.

 

1 packets received by filter
0 packets dropped by kernel

Vedaant
Staff
Staff

Hello @Mirza_Asad2723 , 

Can you verify if both the ISP routes (WAN )are active on the FortiGate 
# get router info routing-table database

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors