Hello everyone.
We have two FortiGate 100F devices configured in active/passive mode.
We are using six site-to-site IPsec tunnels, as well as remote users (Windows/Linux) who connect via FortiClient VPN.
In addition, there are users who connect from Android phones using FortiClient VPN for Android.
About a month ago, the FortiGate devices were automatically updated overnight to FORTIOS v7.6.5 build 3651.
After the update, external users lost the ability to connect via FortiClient VPN on Windows laptops.
After reconfiguring the VPN settings and switching back to DH group 5, Windows laptops were able to connect again.
However, FortiClient VPN on Android still cannot connect and returns an error.
On FortiClient for Android, only the following DH groups are available: 1, 2, 5, and 14.
I tried all of these DH groups one by one, but there was no improvement.
I tested this on multiple Android devices, and also tried the full FortiClient VPN version.
In all cases, I receive the same error in a loop (the connection attempt keeps repeating).
IKE V=root:Negotiate ISAKMP SA Error:
IKE V=root:0:3e35c70729dfedef/0000000000000000:8398: no SA proposal chosen
IKE V=root:0:!NEW_VPN_Orange_0: NAT keep-alive 39 XXX.XXX.XXX.XXX->172.21.3.17:4500.
IKE 0:!NEW_VPN_Orange_0:8389: out FF
IKE V=root:0:!NEW_VPN_Orange_0:8389: sent IKE MSG (keepalive): XXX.XXX.XXX.XXX:4500->172.21.3.17:4500, len=1, VRF=0, id=ff00000000000000/4100000000000000:55000000
IKE V=root:0:!NEW_VPN_Orange_0: NAT keep-alive XXX.XXX.XXX.XXX->172.21.3.17:4500.
IKE 0:!NEW_VPN_Orange_0:8389: out FF
(The real IP address has been changed to XXX)
before this update ( v7.6.5 build 3651) everything was working.
What else can we try to resolve this issue?
Thank you in advance
IKE V=root:Negotiate ISAKMP SA Error:
IKE V=root:0:3e35c70729dfedef/0000000000000000:8398: no SA proposal chosen
This means your phase 1 configuration isn't matching. In the debugs there should be more information from the connection attempt regarding the proposals that the Android devices present and they need to match.
It looks similar issue with: https://community.fortinet.com/t5/Support-Forum/IPsec-VPN-connection-issue-on-FortiClient-Android-af...
"This appears to have been already reported and is currently being investigated. The available workaround for now is to downgrade to 7.6.4 and below."
| User | Count |
|---|---|
| 2895 | |
| 1449 | |
| 850 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.