Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kevin_Noble
New Contributor

Windows 7 64 bit & 64 bit Forticlient Issues

It seems like we cannot negotiate an IPSEC VPN connection to our Fortigate 80C running 4.0 MR3 Patch 5. We are also using the latest Forticlient. The same Fortigate 80C works fine when we connect with Windows XP 32 bit and the 32 bit Forticlient, but we have had no luck getting a laptop with Windows 7 64 bit with a 64 bit Forticlient connected. The VPN monitor on the Fortigate 80C shows the IPSEC connection starting but it never fully negotiates and connects. Has anybody else had trouble with 64 bit versions of Windows 7 and Forticlient?
4 REPLIES 4
L_FTNT
Staff
Staff

Which version of the FCT you are using? 4.2 or 4.3? In general, Windows 7 64bits should be OK to use FCT VPN with FortiOS 4.3.5. Your problem is most likely has something to do with the environment that Windows 7 64bits laptop has, for example, do it has a third party security software installed? Any other VPN clients? In the past, we discovered some third party security software or some VPN client are not compatible with FCT and this has caused some VPN connection issues. L.Clarke
Ling Lu
Kevin_Noble
New Contributor

We got it working on the 4.2 client by reinstalling the FortiClient software so something something must have got missed on the first install. We are still having problems with the 4.3.X.X client connecting but the client software has changed quite a bit so it may just be a matter of knowing how to set it up properly. We don' t have any other third party VPN clients on the Windows 7 machine we are trying it on and we the 4.2 client works with the anitivirus software on the Windows 7 machine.
L_FTNT
Staff
Staff

Right, I can see why the configuration might be an issue. By default, the FCT 4.3 client uses mode_config for the IPsec VPN connections. If you manually create a connection from the client, it may not work for your configuration on the FortiGate if it does not uses mode_config. Since have a working 4.2 client configuration, here is what you can do to simplify the manual configuration on the 4.3.xx client: a) use the VPN editor tool from 4.3.xx to export the 4.2 VPN configuration and then convert it to the 4.3 format b) import the .conf file to the 4.3.xx client Let me know how it goes, L.C
Ling Lu
Kevin_Noble
New Contributor

Thanks - that was it - your solution worked perfectly. I should mention this is not a 64 bit client issue as I first thought as the 32 bit 4.3.X.X client also has the same issues with that default mode_config setting.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors