Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sandoval
New Contributor II

VPN IPSEC - Firmware 7.4.1

Dear all, good morning. We have a Fortigate 60F on version 7.4.0 with an IPSEC VPN Client to Site configured. In firmware version 7.4.0 the VPN works normally, but when we update to version 7.4.1 or 7.4.2 the VPN stops working, it connects but remains as "0bytes received". Does anyone have any idea what is going on?

4 REPLIES 4
Umer221
Staff
Staff

@Sandoval 

 

Please provide more details, if it is an IPsec site to site or a remote access vpn.

Sandoval
New Contributor II

It's a remote access VPN

Umer221
Staff
Staff

Please run the following commands and then try to connect the IPSec dial-up vpn. Once you see the logs on the FortiGate CLI, then post them here:

CFM-SF-FW # digdiagnose debug disable

CFM-SF-FW # diagnose debug console timestamp enable

CFM-SF-FW # diagnose vpn ike log-filter name "S2S-VPN"    (Specify tunnel name)

CFM-SF-FW # diagnose debug application ike -1

Debug messages will be on for 30 minutes.

CFM-SF-FW # diagnose debug enable

pkumari
Staff
Staff

@Sandoval , do you face this issue for all the users?

Please also provide Forticlient debug along with the IKE debug provided by @Umer221 

https://community.fortinet.com/t5/FortiClient/Technical-Tip-How-to-generate-and-export-Debug-logs-fr...

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors