Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
eliaslatif
New Contributor II

Unable To Connect VPN

Hi Guys,

 

I have 100D firewall the SSL VPN was working fine, But for Some reason I removed it and connected the other firewall 60D for few days, and kept 100D aside for few days without making any changes. 

 

Now when I am trying to connect the 100D firewall the SSL VPN From Outside is Not working I am not able to Connect to the VPN with Forticlient it stops at 10% and I am getting Error " Unable to Establish the VPN Connection. The VPN server may be Unreachable"   however I am able to browse the web Access from internal Network and I am able to login.

 

1)I have reinstalled and installed the Forticlient.

2) Not Made any Changes to VPN settings as I Said Earlier. 

3)Note The Public IP is DHCP and it is changed.

4) I also tried to connect with Remote gateway IP which the Public IP of the Firewall and hostname still same issue it doesn't connect and stops at 10% and gives error.

 

Can anyone please help  

7 REPLIES 7
ozkanaltas
Valued Contributor II

Hello @eliaslatif ,

 

Can you access your ssl-vpn portal via browser from the internet?

 

If you say yes, it might be your FortiClient settings aren't correct. Sometimes FortiClient can't save customized port settings. Can you check that area? 

 

Also, you say "public IP is DHCP and changed" What do you mean by that? 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
eliaslatif

Hello Ozkan Thanks again for you quick response.

 

1) i am able to access the vpn web from internal network not from outside. https://10.39.1.13:10443 

 

2) I have not made any changes as I removed the firewall and kept as it is the SSL VPN was working fine earlier.

 

3)the Public IP given by service provider is DHCP its Not Static If The Device is Rebooted the IP changes Everytime. But it should not be an issue because the device rebooted multiple times earlier and the SSL VPN was working fine without any issues.

 

any thing Related to policy ? Should I delete the VPN policy and create again ? 

 

Any suggestions?

 

Bad Day For Me, Mistakenly Disabled LAN Interface and Now on the Other Firewall the VPN is Not Working.. 🥲

ozkanaltas
Valued Contributor II

Hello @eliaslatif ,

 

As I understand, there is an ISP router(or modem) in front of FortiGate. Can you check this router configuration? If you want to access your FortiGate from outside you need to configure dnat on your ISP router. Maybe your FortiGate IP address has changed and you need to configure your isp router with this IP address.

 

I think your ssl-vpn configuration is correct. Because You say, I can access and login the ssl-vpn portal internally. That indicates everything works well. 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
ezhupa

Hello,

 

Running a sniffer on the FGT device might help see if indeed any packets are arriving at the FGT at all. If not, most likely the modem/router before the FGT might be dropping the packets and not allowing the VPN to get formed. 

Also when you say from the "Outside" you mean externally fro the FGT itself so from the internet? In that case what IP are you using on your FCT to connect to? 
The  DHCP IP on the FGT or the public IP on the modem/router?


eliaslatif
New Contributor II

Ezupa,

 

Yes outside means from external network I am not able to access the VPN, Within the Fortigate Network I am able to Access the Web VPN and I am able to Login in to it . I am using the same (public ip address ISP IP) / xyzfortidyndns.com as remote gateway to connect from Forticlient. It was working absolutely fine.

 

It looks like other Fortigate firewall of ISP provider Might be dropping the packet.  ill call the ISP shortly and aks them to check. thanks A lot 

eliaslatif
New Contributor II

Thanks Ozkan and ezhupa, you guys are correct as I am working on it remotely, I just came to know that there is another Fortigate firewall of the ISP Provider which might be dropping the packet. Should I call them and tell them to enable Dnat On that Device as well ? Please suggest anything else which I need to ask them to check, so I can call them ask them to enable the settings accordingly.

 

Thanks in Advance.

PCMPERU
New Contributor

Hello, were you able to resolve your issue? I am experiencing the same problem. The only difference is that I have a static IP

Labels
Top Kudoed Authors