hi there,
need help please.
we use fg60d and fg30e. all with firmware 5.6.2
after upgrade fortios, clients can't vpnssl from their computer.
version forticlient 5.6.6 ; antivirus kaspersky, windows 7 sp1.
complete error message is:
--------------------------- Warning --------------------------- Your PC does not meet the host checking requirements set by the firewall. Please check that your OS version or antivirus and firewall applications are installed and running properly or you have the right network interface. (-455) --------------------------- OK ---------------------------
but I can connect vpnssl using my moble phone (android based).
any advice?
thanks in advance.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Are they local users? Or RADIUS/TACACS/LDAP users who are authenticated by outside servers? If local, you might have lost password after the upgrade. I heard about an 5.6 upgrade issue that might wipe out all vpn PSK passwords. It might happened to local user passwords.
First you need to check if it's still there or not with "show user local". Then if they're gone, copy and paste the password statement (with ENC password) from your backup config file.
hi,
have tried to change password, create new user.
still same, the error message msg="SSLVPN tunnel connection failed (Error=-455).
when first install forticlient 5.6.6, got same error message. so after I update my windows. try connect and it's works.
now when I want to connect again, it shown that error. windows has latest update, so do with antivirus.
tried everything...but can't work...
just amaze with new forticlient...why this happen..
You can try multiple things but likely need to open a TAC case with the FortiGate.
Those things are:
- sslvpn app debugging at FG (diag debug app sslvpn -1)
- FortiClient local log (set "debug" level and take all VPN log)
- downgrade FC5.6.6 to something lowler, like 5.6.0, 5.6.1, ...
Probably you don't want to downgrade FG itself to the previous version.
One more thing: Since any SSL VPNs don't seem to work any more, make sure you didn't lose SSL VPN config itself during the upgrade: settings, portals, and policies w/ the user group(s).
Hi, I have also had a similar issue and I solved by changed some configuration in internet explore. go to internet explorer, settings, internet options, advanced and checkbox all TLS version.
It was right at the screen in the original post. I read it in email, which was truncated, and didn't read the entire post when I responded. The new version likely allow only higher TLS levels. You can reenable disabled one with "set slsv1-0 enable" and so on under "config vpn ssl settings" but raising the capability on the client side like Daniel did is the right way.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1643 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.