Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
lucas_h_
New Contributor

Uable to establish SSL VPN connection using Fortinet SSL VPN Client 6.4 under windows 10

HI, I have installed the new Fortinet SSL VPN Client (6.4) on several machines with different operating systems. The client works fine on Linux and MacOS, but throws an error when I try to connect under Windows 10. This is the error: "Unable to establish the VPN connection. The VPN server may be unreachable.(-14)." I am using an aws fortigate instance and the authentication is established using the radius protocol / a radius server. It works on Windows 10 when I install an older version of the SSL VPN client (6.0), but I need to upgrade the client on all systems. Does anyone have an idea as to why this could be happening?

Thank you in advance for any help!

 

The error message seems pretty generic, so here are my logs from the login attempt:

 

2020-08-05 10:55:33 2020-08-05 10:55:33 [615] fnbamd_pop3_start-user.name [161:root:694e]fam_auth_send_req:896 task finished with 4 2020-08-05 10:55:33 [640] __fnbamd_cfg_get_radius_list_by_group-Loading RADIUS server 'DIU-RADIUS' for usergroup 'Radius' (2) 2020-08-05 10:55:33 [307] fnbamd_create_radius_socket-Opened radius socket 15 2020-08-05 10:55:33 [307] fnbamd_create_radius_socket-Opened radius socket 16 2020-08-05 10:55:33 [1362] fnbamd_radius_auth_send-Compose RADIUS request 2020-08-05 10:55:33 [1329] fnbamd_rad_dns_cb-18.194.159.20->18.194.159.20 2020-08-05 10:55:33 [1304] __fnbamd_rad_send-Sent radius req to server 'DIU-RADIUS': fd=15, IP=18.194.159.20(18.194.159.20:1812) code=1 id=159 len=136 user="user.name" using MSCHAPv2 2020-08-05 10:55:33 [284] radius_server_auth-Timer of rad 'DIU-RADIUS' is added 2020-08-05 10:55:33 [723] auth_tac_plus_start-Didn't find tac_plus servers (0) 2020-08-05 10:55:33 [444] ldap_start-Didn't find ldap servers (0) 2020-08-05 10:55:33 [580] create_auth_session-Total 1 server(s) to try 2020-08-05 10:55:34 [2440] fnbamd_auth_handle_radius_result-Timer of rad 'DIU-RADIUS' is deleted 2020-08-05 10:55:34 [1762] fnbamd_radius_auth_validate_pkt-RADIUS resp code 2 2020-08-05 10:55:34 [2466] fnbamd_auth_handle_radius_result-->Result for radius svr 'DIU-RADIUS' 18.194.159.20(1) is 0 2020-08-05 10:55:34 [2390] fnbamd_radius_group_match-Passed group matching 2020-08-05 10:55:34 [1057] find_matched_usr_grps-Group 'Radius' passed group matching 2020-08-05 10:55:34 [1058] find_matched_usr_grps-Add matched group 'Radius'(2) 2020-08-05 10:55:34 [190] fnbamd_comm_send_result-Sending result 0 (error 0, nid 0) for req 1315710889, len=2060 2020-08-05 10:55:34 2020-08-05 10:55:34 [161:root:694e][fam_auth_proc_resp:1257] Authenticated groups by FNBAM: 2020-08-05 10:55:34 [736] destroy_auth_session-delete session 1315710889 [161:root:694e]auth_rsp_data.grp_list[0] = Radius 2020-08-05 10:55:34 [161:root:694e]Auth successful for user user.name in group Radius 2020-08-05 10:55:34 [2731] handle_req-Rcvd 7 req 2020-08-05 10:55:34 [161:root:694e]fam_do_cb:659 fnbamd return auth success. 2020-08-05 10:55:34 [306] fnbamd_acct_start_START-Error getting radius server 2020-08-05 10:55:34 2020-08-05 10:55:34 [161:root:694e][1472] create_acct_session-Error start acct type 7 2020-08-05 10:55:34 SSL VPN login matched rule (1). 2020-08-05 10:55:34 [161:root:694e][2745] handle_req-Error creating acct session 7 User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}]) 2020-08-05 10:55:34 [161:root:694e]rmt_web_session_create:826 create web session, idx[15] 2020-08-05 10:55:34 [161:root:694e]login_succeeded:530 redirect to hostcheck 2020-08-05 10:55:34 [161:root:694e]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}]) 2020-08-05 10:55:34 [161:root:694e]deconstruct_session_id:426 decode session id ok, user=[user user.name],group=[Radius],authserver=[DIU-RADIUS],portal=[full-access],host=[31.16.214.116],realm=[],idx=15,auth=2,sid=2d7e83b2,login=1596617734,access=1596617734,saml_logout_url=no 2020-08-05 10:55:34 [161:root:694e]deconstruct_session_id:426 decode session id ok, user=[user user.name],group=[Radius],authserver=[DIU-RADIUS],portal=[full-access],host=[31.16.214.116],realm=[],idx=15,auth=2,sid=2d7e83b2,login=1596617734,access=1596617734,saml_logout_url=no 2020-08-05 10:55:34 [161:root:694e]deconstruct_session_id:426 decode session id ok, user=[user user.name],group=[Radius],authserver=[DIU-RADIUS],portal=[full-access],host=[31.16.214.116],realm=[],idx=15,auth=2,sid=2d7e83b2,login=1596617734,access=1596617734,saml_logout_url=no 2020-08-05 10:55:34 [161:root:694e]req: /remote/fortisslvpn 2020-08-05 10:55:34 [161:root:694e]deconstruct_session_id:426 decode session id ok, user=[user user.name],group=[Radius],authserver=[DIU-RADIUS],portal=[full-access],host=[31.16.214.116],realm=[],idx=15,auth=2,sid=2d7e83b2,login=1596617734,access=1596617734,saml_logout_url=no 2020-08-05 10:55:34 [161:root:694e]rmt_web_access_check:712 access failed, uri=[/remote/fortisslvpn],ret=4103, 2020-08-05 10:55:34 [161:root:694e]req: /remote/login 2020-08-05 10:55:34 [161:root:694e]rmt_web_auth_info_parser_common:461 no session id in auth info 2020-08-05 10:55:34 [161:root:694e]rmt_web_get_access_cache:793 invalid cache, ret=4103 2020-08-05 10:55:34 [161:root:694e]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}]) 2020-08-05 10:55:34 [161:root:694e]get_cust_page:126 saml_info 0 2020-08-05 10:55:34 [161:root:694e]req: /FortiClientSslvpnClearCacheUrl/for/Wini 2020-08-05 10:55:34 [161:root:694e]def: (nil) /FortiClientSslvpnClearCacheUrl/for/WininetLibrary/1/2/3/4/5/6/7/8/9/0/a/b/c/d/e/f/g/h/i/j/k/l/m/n/o/p/q/r/s/t 2020-08-05 10:55:36 [161:root:0]RCV: LCP Echo_Request id(228) len(8) [Magic_Number ff757419] 2020-08-05 10:55:36 [161:root:0]SND: LCP Echo_Reply id(228) len(8) [Magic_Number 0b9dc7b6] 2020-08-05 10:55:37 [161:root:6948]req: /remote/portal?action=1

Thank you, Lucas

2 REPLIES 2
poundy
Contributor

I've just run into a similar issue connecting to someone else's FGT VPN server, and I constantly got that error at the 80% mark in the negotiation, which stops at the same point if you use the incorrect password for example. For me, I went to the endpoint via a browser, and signed in with that user. As part of that I added the site to my IE trusted site list (old skool, I know). But after I had successfully signed in from that device via browser, I could then open the forticlient connection. Might be worth a shot ?

(I hate not being able to more technically describe what "fixed" this for me)

lucas_h_

I am facing the exact same issue, but the procedure you described doesn't seem to work for me unfortunately. Thank you for the advice though, it was definitely worth a try!

Labels
Top Kudoed Authors