Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
pollognr911
New Contributor

Users cannot log in to Forticlient on their computer but can on others

Dear Sirs, please help me with this problem that occurred today. I have 5 users who have not been able to log in to Forticlient on their Windows computers. The VPN reaches 40% and then returns to the credentials stage, without displaying an error message.

The same test is performed on another computer within the community and outside the company domain and the user does connect, but doing so from those computers does not succeed.

Windows updates have been checked, keeping them up to date, uninstalling the VPN and reinstalling it, connecting to different networks, re-entering passwords in Active Directory and the problem persists on those computers.

The laptops are from different brands and are on Windows 11.

When validating the logs in the firewall, it shows me user attempts N/A and in the action ssl-exit-error and in Reason N/A.

5 REPLIES 5
adambomb1219
SuperUser
SuperUser

What version of FortiOS?  What version of FortiClient?  What is the auth method?  RADIUS? Local?  what is the MFA strategy here?  Why isn't a SAML IDP being used? 

pollognr911

Hello, the version is v7.2.10 build 1706 (Mature) FortiGate 100F. The Forti Client versions that have been tested are from 4.2.4.0972 to 7.4.1.1736 and 7.4.0.1658. We have users on Azure with SAML and locally. We do not use MFA and IDP SAML is not used for these users. But consider that it is not allowing users to authenticate on those computers, but when validating the users on other computers, the connection can be achieved.

sjoshi
Staff
Staff

please check if tls 1.2 1.3 is enable on the pc

when you say that the same cred works fine from another machine then that isolates FGT issue and issue is on the end machine.

try to take FCT diagnostic output..that will give you some clarity

Let us know if this helps.
Salon Raj Joshi
pollognr911

Hello, the laptop with the problem was checked and it has TLS 1.2 and 1.3 by default.
Now we are trying to enable WEB mode in the VPN and the user I am using is validating if it was able to authenticate.

sjoshi

yes you can try with the web mode

try checking forticlient diagnostic logs too

https://docs.fortinet.com/document/forticlient/7.4.1/administration-guide/748524/diagnostic-tool

Let us know if this helps.
Salon Raj Joshi
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors