Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nivesh
New Contributor

Unable to connect forticlient VPN

Hi I' m able to connect to the VPN for a few seconds and it disconnects showing a gateway error kindly find below the log generated <Type>Warning <Time>7/17/2014 11:35:39 AM <Source>WebFilter enter CWebFilterInterface::readSettings() <Type>Warning <Time>7/17/2014 11:35:39 AM <Source>WebFilter (repeated 1 times in last 0 sec) enter CWebFilterInterface::readSettings() <Type>Warning <Time>7/17/2014 11:35:39 AM <Source>WebFilter Unable to retrieve the webfilter UDP port number. <Type>Warning <Time>7/17/2014 11:36:28 AM <Source>VPN loc_ip=192.168.1.2 loc_port=500 rem_ip= rem_port=500 out_if=0 vpn_tunnel= status=negotiate_error msg=" No response from the peer, phase1 retransmit reaches maximum count.... " <Type>Warning <Time>7/17/2014 11:36:35 AM <Source>WebFilter enter CWebFilterInterface::readSettings() <Type>Warning <Time>7/17/2014 11:36:35 AM <Source>WebFilter (repeated 1 times in last 0 sec) enter CWebFilterInterface::readSettings() <Type>Warning <Time>7/17/2014 11:36:35 AM <Source>WebFilter Unable to retrieve the webfilter UDP port number. Someone has any idea how we can resolve it Thank you
3 REPLIES 3
Nihas
New Contributor

Q1) Can you please confirm , you are using an external facing interface ( WAN) as local interface in Phase 1 ? Q2) How is your WAN interface configured? Is it configured with 192.168.1.2? Do you have any router with 192.168.1.1 IP, where internet is terminated? Q3) How about your ISP? Do you have a static IP? If we get these details , we can sort out the issue!
Nihas [\b]
Nihas [\b]
nivesh
New Contributor

Hi Nihas Please find the details below Q1) Can you please confirm , you are using an external facing interface ( WAN) as local interface in Phase 1 ? -Yes trying to access external with a local interface Q2) How is your WAN interface configured? Is it configured with 192.168.1.2? Do you have any router with 192.168.1.1 IP, where Internet is terminated? I have just installed the forticlient and imported the vpn connection details.yes the router has an ip 192.168.1.1 and use the same router for accessing Internet too. Q3) How about your ISP? Do you have a static IP? ADSL and I don’t use an static ip.
Nihas
New Contributor

If you are looking for a stable VPN environment you have to configure your firewall as an end device instead of the router..! And my suggestion is that do not use 192.168.1.0 /192.168.0.0 networks anywhere in an office environment. The problem is, most of the networking devices which are using in home has a default LAN with those sub nets. And you will get overlapping issues while configuring /accessing through VPN' s. 1) First of all , you need a STATIC IP / FQDN to use IPSec Dialup VPN. 2) you need to forward the UDP ports 500 &4500 in " Router" to the Firewall WAN port ( Which you are using as the local interface in Phase 1) 3) Make sure you have a policy in firewall for accepting the communications from the " VPN interface" And few more questions- How did you dial to the IPSec VPN if you don' t have any STATIC IP? What is the firewall model and router you have? Which ForiOS you are using in Firewall? What is the IP Range for VPN user?
Nihas [\b]
Nihas [\b]
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors