Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MSO_Andy
New Contributor

Unable to establish the VPN connection. The VPN server may be unreachable.

I know this is a common error, but I' m having a hard time tracking down the cause for our particular setup. I' ve tested it on a variety of different OS' s (Vista, 7,8) and a few versions of the Forticlient program, but we always get this result when connecting from any PC recently. The setup had been working fine previously, though we had seen this error before a couple of times (normally a reboot sorted it out). I know that Teamviewer and other VNC clients are known to cause issues, but I' ve been testing this on a machine with no clients installed and windows firewall disabled and still get the same error. What makes it stranger is that we can consistently connect to our Fortigate VPN when using the iPad' s inbuilt VPN software. Any assistance you could give would be much appreciated! Thanks!
6 REPLIES 6
MSO_Andy
New Contributor

Just a bit more detail- I have disabled all logging in Fortigate as I' d heard extensive logging can cause this issue, but I' m still having the same issue.
MSO_Andy
New Contributor

It' s ok, we' ve got it sorted now. It was in relation to a firmware upgrade to patch up the HeartBleed vulnerability.
JACA_CH

Hello,

I also have a problem with connection to VPN server. A week ago everything was OK and yestarday I tried to connect via Forticlient and I recive a notice:

"Unable to establish the VPN connection. The VPN server may be unreachable. (-5)"

VPN server is OK

 

My OS is Windows Vista Home Premium

Forticlient ver. 5.2.5.0658

I tried to uninstall and install again Forticlient but it didn't help.

 

What I should check? And how to solve this problem?

rwpatterson
Valued Contributor III

You really shouldn't add onto a two year old thread. The solution will be totally different, I would imagine.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
emnoc
Esteemed Contributor III

It could b any of the following;

 

wrong port

local filterting

wrong ipv4 address

sslvpnd  has stop

missing fw-policies

etc...

 

 

If you have access to the fortigate cli , diag sniffer packet <name of wan interface > "host x.x.x.x" where x.x.x.x is the window client that your expecting to see.

 

Based on the findings or lack of findings, you will proceed to the above listed items.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
JACA_CH
New Contributor

emnoc wrote:

It could b any of the following;

 

wrong port

local filterting

wrong ipv4 address

sslvpnd  has stop

missing fw-policies

etc...

 

- Port is OK. There is a dedicated 8443 port for this connection.

- Local filtering? I don't know what you mean.

- IP address is OK, beacuse I have another computer (little netbook) and from this netbook I can connect to this VPN server using port 8443 and IP 80.48.233.220. Something has happend on my basic notebook.

- sslvpnd  has stop - ???

I don't know how to check it. But in the Forticlient log I have found this notice:

"2016-02-06 21:00:13 Error VPN id=96603 msg="SSLVPN tunnel connection failed (Error=-5)." remotegw=80.48.233.220 vpnstate=connected vpntunnel=VECTOR vpntype=ssl vpnuser=JacekC"

Maybe it will help to analize this problem.

Labels
Top Kudoed Authors