Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bthalpin
New Contributor

fortivpn creates tunnel but does not connect (Debian)

With forticlient 7.4.0.1636 on a laptop running a new install of Debian 12, the VPN connection process seems to complete normally but there is no traffic (bytes received remain at zero). Inspection of the logs shows no apparent problems, but I cannot connect to the remote systems ("no route to host").

 

But if I do "nmcli device status" I see that a fctvpn tunnel has been created. I can manually connect this by doing something like:

 

sudo ip route add 10.100.123.123 dev fctvpnf01234567

 

After this I can access the specified host as normal, and the traffic counts update.

 

Any ideas why the normal connection process is not completing?

1 Solution
AEK

If you can't contact FG admin then you have to add the route manually as you did above.

You can still try older FortiClient VPN version like 7.0.x, which has less issues that 7.4.x.

AEK

View solution in original post

AEK
3 REPLIES 3
AEK
SuperUser
SuperUser

The route is obviously not being injected to your routing table

On your FG, check the used SSL-VPN portal config. Under tunnel mode, you may enable split tunnel and add the routing addresses (e.g.: 10.100.123.0/24). This will inject a route to this network into your routing table.

AEK
AEK
bthalpin
New Contributor

Thanks, but I don't have access to the system side; I'm only an end-user.

 

However, I don't think it's a system-side problem: I can access as normal from several android devices, and could from a similarly-configured Ubuntu laptop up to two weeks ago (when I last had access to it).

 

OTOH, this gives me (as an end-user) a clean way to configure split-tunnel access, so maybe I shouldn't complain.

AEK

If you can't contact FG admin then you have to add the route manually as you did above.

You can still try older FortiClient VPN version like 7.0.x, which has less issues that 7.4.x.

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors