Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Damien
New Contributor

constantly disconnected from the vpn ssl

 3/4 out of 50 users are constantly disconnected from the vpn ssl 

 

 

what are the settings I can check ?

 

thank you for your help

 
8 REPLIES 8
seadave
Contributor III

If you have a FAZ look for the reason as "Lost the connection"

 

Mar 24 14:49:03 172.16.x.x logver=600098661 timestamp=1585086540 tz="UTC-7:00" devname="FG5H1E" devid="FG5H1Exxxxxxx" vd="root" date=2020-03-24 time=14:49:00 logid="0101039425" type="event" subtype="vpn" level="information" eventtime=1585086540 logdesc="SSL VPN tunnel down" action="tunnel-down" tunneltype="ssl-web" tunnelid=1429696930 remip=x.x.x.x user="user" group="SSL_VPN_FULL" dst_host="N/A" reason="Lost the connection" duration=12156 sentbyte=0 rcvdbyte=0 msg="SSL tunnel shutdown"   If you have a FAZ or SIEM I'd attempt to correlate if these users are coming from a similar ISP.  Or perhaps all those folks are on crappy DSL?  Or people with problems have the same FortiClient version?  Also check your build.  What are you on right now?  We went to 6.0.9 recently and a VPN bug required us opening a ticket with Fortinet to get a pre 6.0.10 build (v6.0.9 build8661) to fix it.  
AnotherUser

I have the same problem, do you solve it?

seadave

Make sure you are on at least 6.0.10. .9 was super buggy. We recently had this issue again after 150 days of uptime. We used the daily restart command to schedule a reboot outside of our production window. Conf sys global Set daily-restart enable Set restart-time 02:00 End Exit You need to remember the next day to log back into the cli and change to set daily-restart disable or it will reboot every night!
seadave

https://kb.fortinet.com/kb/viewContent.do?externalId=FD31055
AnotherUser

I have 6.2.4, i think i have downgrade, but i need that version, the 6.0.10.

 

Thanks a lot!

seadave

I wouldn't downgrade.  Versions are too different.  I'd try a version newer than 6.2.4 and see how that helps.  I think they are on 6.2.5 now.

seadave

When you downgrade you can loose some newer features and even the config UNLESS you have a backup from the version you are reverting to.  In all the years I've used Fortigates (16 years) I've never done a downgrade.  It can be done, but be careful with your config backups.  Good luck. 

 

seadave

These are all the SSLVPN Bugs resolved in 6.2.5

https://docs.fortinet.com/document/fortigate/6.2.5/fortios-release-notes/289806/resolved-issues

 

Bug ID

Description

595505

FortiGate does not send client IP address as a framed IP address to RADIUS server in RADIUS accounting request message.

600029

Sending RADIUS accounting interim update messages with SSL VPN client framed IP are delayed.

604772

SSL VPN tunnel is unexpectedly down sometimes when certificate bundle is updated.

606271

Double redirection through SSL web mode not working.

607687

RDP connection via SSL VPN web portal does not work with UserPrincipalName (UPN) and NLA security.

608464

Get 305 error when browsing website through SSL VPN web mode bookmark and sslvpnd crashes.

610579

Videos from live cameras via SSL VPN web mode not working.

617170

[link]https://outlook.office365.com[/link] cannot be accessed in SSL VPN web portal.

620508

CLI command get vpn ssl monitor displays users from other VDOM.

622068

Adding FQDN routing address in split tunnel configuration injects single route in client for multiple A records.

622110

SSL VPN disconnected when importing or renaming CA certificates.

622871

SSL VPN web mode not displaying full customer webpage after logging in.

623076

Add memory protection for web mode SSL VPN child process (guacd).

623231

Pages could not be shown after logging in to back-end application server.

623379

Memory corrupt in some DNS callback cases causes SSL VPN crash.

624145

An internal website via SSL VPN web portal failed to load an external resource.

624899

Log entry for tunnel stats shows wrong tunnel ID when using RDP bookmark.

625301

Riverbed SteelCentral AppResponse login form is not displaying in SSL VPN web mode.

628821

Internal aixws7test2 portal is not loading in SSL VPN web mode.

629190

After SSL VPN proxy, some JS files of hapi website could not work.

629373

SAML login button is lost on SSL VPN portal.

631130

Internal site [link]http://va***.com[/link] not completely loading through SSL VPN web mode bookmark.

633812

For guacd daemon generated for RDP session, it would sometimes be in an unknown state with 100% CPU and could not be released.

634991

Internal server error 500 while accessing contolavdip portal in SSL VPN web mode.

635307

Map could not be displayed correctly in SSL VPN web mode.

636984

Website (pr***.com) not loading properly in SSL VPN web mode.

637018

After the upgrade to 6.0.10/6.2.4/6.4.0, SSL VPN portal mapping/remote authentication is matching user into the incorrect group.

638733

Internal website hosted in bookmark [link]https://in***.cat[/link] is not loading completely in SSL VPN web mode.

648369

Some JS files of jira.***.vwg could not run in SSL VPN web mode.

649130

SSL VPN log entries display users from other VDOMs.

654534

SAML authentications occurring through SSL VPN web mode are not completing

 

Labels
Top Kudoed Authors