Dear Sirs, please help me with this problem that occurred today. I have 5 users who have not been able to log in to Forticlient on their Windows computers. The VPN reaches 40% and then returns to the credentials stage, without displaying an error message.
The same test is performed on another computer within the community and outside the company domain and the user does connect, but doing so from those computers does not succeed.
Windows updates have been checked, keeping them up to date, uninstalling the VPN and reinstalling it, connecting to different networks, re-entering passwords in Active Directory and the problem persists on those computers.
The laptops are from different brands and are on Windows 11.
When validating the logs in the firewall, it shows me user attempts N/A and in the action ssl-exit-error and in Reason N/A.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
What version of FortiOS? What version of FortiClient? What is the auth method? RADIUS? Local? what is the MFA strategy here? Why isn't a SAML IDP being used?
Hello, the version is v7.2.10 build 1706 (Mature) FortiGate 100F. The Forti Client versions that have been tested are from 4.2.4.0972 to 7.4.1.1736 and 7.4.0.1658. We have users on Azure with SAML and locally. We do not use MFA and IDP SAML is not used for these users. But consider that it is not allowing users to authenticate on those computers, but when validating the users on other computers, the connection can be achieved.
please check if tls 1.2 1.3 is enable on the pc
when you say that the same cred works fine from another machine then that isolates FGT issue and issue is on the end machine.
try to take FCT diagnostic output..that will give you some clarity
Hello, the laptop with the problem was checked and it has TLS 1.2 and 1.3 by default.
Now we are trying to enable WEB mode in the VPN and the user I am using is validating if it was able to authenticate.
yes you can try with the web mode
try checking forticlient diagnostic logs too
https://docs.fortinet.com/document/forticlient/7.4.1/administration-guide/748524/diagnostic-tool
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.