Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tolgainci
New Contributor II

Unable to connect Forticlient VPN

Hello,

 

We are based in Turkey, and a user in Kazakistan is unable to connect to VPN. Other users in Turkey and other countries such as Thailand are able to connect with the same username and password. The exact error we get is "Unable to establish the vpn connection. the vpn server may be unreachable. (-5010)" I couldn't find anything on error 5010.

 

We tried connecting via cellphone, connecting from a public internet but the error is still the same. Then we formatted the computer, it's still the same. I will be glad if someone can help. Thanks in advance.

10 REPLIES 10
AEK
SuperUser
SuperUser

Hi

First thing to try from the affected client:

telnet x.x.x.x:pppp

Where x.x.x.x is the FGT public IP address for VPN access, and pppp is the port number of the VPN service.

You can also try from browser:

https://x.x.x.x:pppp

 

AEK
AEK
tolgainci
New Contributor II

Hello,

 

telnet 176.xx.xx.xx 10443 connects. Blank screen with blinking cursor.
https://176.xx.xx.xx:10443 doesn't connect. It gives ERR_TIMED_OUT error

AEK

Its clear that the TCP connection is failing to establish.

I see you tried from several ISP with the same result.

Can you check on FGT side if there is no restriction by country in SSL VPN settings?

AEK
AEK
tolgainci
New Contributor II

There is restriction by country, but Kazakistan is selected. Also we tried by disabling all country restrictions but the result was the same.

AEK

Can you enable ping on wan interface and try ping it from Kazakhstan?

AEK
AEK
tolgainci
New Contributor II

Ping works from Kazakhstan

AEK

In that case probably 10443 is blocked from somewhere (ISP? Kazak?). Is such thing possible? You may confirm it if you can temporarily move vpn from 10443 to 443 and test.

AEK
AEK
Atul_S
Staff & Editor
Staff & Editor

Hi there,

 

Since all the other users are working fine, the SSL VPN config seems to be correct at the FortiGate end. It looks to me more like a local user VPN configuration issue, an auth issue, or a latency issue. Are you connecting to this SSL VPN on a standard 443 port? If not, then we might need to rule out a custom port issue upstream. Please review the documents below if you would like to capture some log data and review them.

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-Troubleshooting/ta-p/189542

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-fix-the-error-Unable-to-estab...

 

Thanks,

Atul Srivastava
tolgainci
New Contributor II

Hi,

 

We are using port 10443

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors