Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
KadiatouDiallo
New Contributor II

VPN IPSec configuration on Fortigate 90G

Hello,

I need help to configure IPsec VPN on my FortiGate.

I have created the users and configured the tunnel, but I can't access it via FortiClient.

I really need your help.

 

14 REPLIES 14
funkylicious
SuperUser
SuperUser

Hi,

Can you please share the output of the ipsec configuration ( and sanitize/hide sensitive information like public IP and PSK ) and describe the issue that you have ?

show vpn ipsec phase1-interface

show vpn ipsec phase2-interface 

"jack of all trades, master of none"
"jack of all trades, master of none"
KadiatouDiallo

The following are my config:

 

image.pngimage.pngimage.pngimage.png

funkylicious

ok, base on your output the forticlient vpn configuration should look something like this :

where the Pre-shared key is what you have configured and if you have a peer id configured you should put it in the Local ID field.

 

afterwards, you should have firewall rules from the source interface Access-Distant and source address object range 172.16.10.10-172.16.10.20 to whatever destination interface and destination object you need.

 

L.E. in order to try and debug the issue that you have, you should look at https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-IPsec-VPN-tunnels/ta-p/195955 and start the debug, then initiate a connection.

 

Screenshot 2025-04-23 at 14.25.24.pngScreenshot 2025-04-23 at 14.26.16.pngScreenshot 2025-04-23 at 14.26.44.png

"jack of all trades, master of none"
"jack of all trades, master of none"
KadiatouDiallo

Yes, but it doesn't work.

 

funkylicious

you would need to share some debug output and share more info about the issue that you encounter while trying to connect.

 

since it's a private ip configured on wan, are you trying to connect from lan and test it ? if so, do you have a firewall policy between the network segments that allows the connection ?

"jack of all trades, master of none"
"jack of all trades, master of none"
KadiatouDiallo

When I test access via Forticlient, I get the following error message: "The VPN connection to the cloud was not established."

What could be causing this?

funkylicious

could be a couple of things.

start by confirming that traffic for IPsec VPN is allowed, using commands from here - https://community.fortinet.com/t5/FortiGate/Technical-Tip-Debug-flow-tool/ta-p/213238 

if everything suggests that traffic is passing then start doing a debug for ipsec using the link above.

you can later share the output of the debugs here.

what version of FortiOS are you running on the 90G ?

"jack of all trades, master of none"
"jack of all trades, master of none"
KadiatouDiallo

v7.0.12

KadiatouDiallo
New Contributor II

My WAN interface has a private address, not a public address.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors