Hello,
I want old connection type to work with the SSLVPN connection of my FortiGate 80C router, with firmware 5.6.3. I found how to activate tlsv1-0 in the SSLVPN, so the FortiClient gets passed the connection credentials, but stops after and returns permission denied. From the SSLVPN web page also, same error from IE 8 after logging in.
I guess tlsv1-0 needs to be allowed somewhere else also. What and where do I modify settings to let Windows XP connect to SSLVPN on this newer firmware?
Thanks.
Why not disable the TLS-v1 in your XP and force it to use the new TLS.
I found how to activate tlsv1-0 in the SSLVPN, so the FortiClient gets passed the connection credentials, but stops after and returns permission denied
Why do you think its tLS v1.0. You state it get's pass credentials so that means something is happening.
run diag debug commands and investigate
diag debug enable
diag debug application sslvpn -1
Your long term should be to look at a newer OS. Forticlient ( latest versions ) are not supported on XP and XP should be eliminated by now ( yes I know many are still out on it ). But in reality MS has a low cost to free upgrade from XP.
PCNSE
NSE
StrongSwan
That computer will eventually get updated to a newer OS, but for now, I need it to connect like it used to. Since it was working fine with previous ForitOS, it can work again. Newer FortiOS disables TLSv1-0, and I found how to reactivate it for SSL-VPN, which is why I can pass credentials now. I guess it needs to be reactivated elsewhere to get through the "permission denied" security block.
I will try the diag debug...
Newer TLS are not available with XP.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1751 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.