Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mdchelpdesk
New Contributor

VPN issue in Hong Kong

Hello everyone!

 

We're a company from Italy and we use Forticlient VPN for our different location all around the world, we've a very serious issue in Hong Kong where we're not able to use it.

 

We use Mac, we just try with a different network (home and personal hotspot) and on a different devices (Macbook, iMac and Windows laptop) with the same result: there's no way to connect to the VPN

 

The error are: unable to estabilish the VPN connection: the vpn server may be unreachable or network error, request timed out.

 

Same settings are in use in London, Paris, and right now from 2 our users that are in California with any issue.

 

Could you please help us to find a solutions about it?

 

Thanks

5 REPLIES 5
Skytech1
New Contributor III

1) Can you ping FortiGate from your host? (Make sure the device is reachable)

2) Do a telnet to the SSL VPN port that FG is using to see if you can reach it, maybe the port is blocked where you are located

3) If 1 and 2 are successfull, then you can follow this tips to troubleshoot

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-SSL-VPN-Troubleshooting/ta-p/189542

 

 

AEK
SuperUser
SuperUser

Hello

Is it working from Hong Kong to Hong Kong?

Try connect with a client connected to the same ISP as your VPN server.

AEK
AEK
mdchelpdesk

Hello there, 

no, doesn't work from hong kong to hong kong

AnthonyH
Staff
Staff

Hello mdchelpdesk,

 

Could you please run a debug flow using the commands below and have the user connect. Please share the outputs here:
di deb disable
di deb res
diagnose debug flow filter clear
di deb flow filter addr <WAN IP>
di deb flow filter port <SSLVPN PORT>
diagnose debug console timestamp enable
diagnose debug flow trace start 200
diagnose debug enable

In addition, could you please share you SSLVPN Settings to this post?
config ssl vpn settings
show full

Technical Support Engineer,
Anthony.
hbac
Staff
Staff

Hi @mdchelpdesk,

 

Can you check whether the traffic is reaching FortiGate or not? You can run packet sniffer as follows by replacing x.x.x.x with the public IP address of HongKong user and try to connect. 

 

di sniffer packet any 'host x.x.x.x' 4 0 l 

 

Regards, 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors