Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
adcapitaladmin
New Contributor

issue android VPN FORTICLIENT and FORTIOS v7.6.5 build 3651

Hello everyone.

We have two FortiGate 100F devices configured in active/passive mode.
We are using six site-to-site IPsec tunnels, as well as remote users (Windows/Linux) who connect via FortiClient VPN.
In addition, there are users who connect from Android phones using FortiClient VPN for Android.
About a month ago, the FortiGate devices were automatically updated overnight to FORTIOS v7.6.5 build 3651.
After the update, external users lost the ability to connect via FortiClient VPN on Windows laptops.
After reconfiguring the VPN settings and switching back to DH group 5, Windows laptops were able to connect again.
However, FortiClient VPN on Android still cannot connect and returns an error.
On FortiClient for Android, only the following DH groups are available: 1, 2, 5, and 14.
I tried all of these DH groups one by one, but there was no improvement.
I tested this on multiple Android devices, and also tried the full FortiClient VPN version.
In all cases, I receive the same error in a loop (the connection attempt keeps repeating).

IKE V=root:Negotiate ISAKMP SA Error:
IKE V=root:0:3e35c70729dfedef/0000000000000000:8398: no SA proposal chosen
IKE V=root:0:!NEW_VPN_Orange_0: NAT keep-alive 39 XXX.XXX.XXX.XXX->172.21.3.17:4500.
IKE 0:!NEW_VPN_Orange_0:8389: out FF
IKE V=root:0:!NEW_VPN_Orange_0:8389: sent IKE MSG (keepalive): XXX.XXX.XXX.XXX:4500->172.21.3.17:4500, len=1, VRF=0, id=ff00000000000000/4100000000000000:55000000
IKE V=root:0:!NEW_VPN_Orange_0: NAT keep-alive XXX.XXX.XXX.XXX->172.21.3.17:4500.
IKE 0:!NEW_VPN_Orange_0:8389: out FF
(The real IP address has been changed to XXX)
before this update ( v7.6.5 build 3651) everything was working.
What else can we try to resolve this issue?

Thank you in advance

2 REPLIES 2
KevinGue
New Contributor III

IKE V=root:Negotiate ISAKMP SA Error:
IKE V=root:0:3e35c70729dfedef/0000000000000000:8398: no SA proposal chosen

This means your phase 1 configuration isn't matching. In the debugs there should be more information from the connection attempt regarding the proposals that the Android devices present and they need to match.

 

HarryTran
Staff
Staff

It looks similar issue with: https://community.fortinet.com/t5/Support-Forum/IPsec-VPN-connection-issue-on-FortiClient-Android-af...
"This appears to have been already reported and is currently being investigated. The available workaround for now is to downgrade to 7.6.4 and below."

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors