Following constellation:
FortiGate with FOS 7.2.10
FortiClient 7.2.5 on windows.
IPsec tunnel witb psk and xauth against ldap usergroup on Authenticator and mode config.
Behavior:
- Tunnel connects
- does psk auth and proposals
- does mode config - gets ip and everything
- initates xauth
- fgt send xauth request to client
Log on FGT reports "Client has not completet xauth challenge" even before the forticlient prompts me for 2nd factor.
Looks like FGT sends the xauth request but does not wait for an answer from client.
Do you have any suggestions?
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Hello,
I would recommend to collect debug traces below while the issue is reproduced:
diagnose debug application fnbamd -1
diagnose debug application ike -1
diagnose debug enable
Moreover, I would also recommend to check FortiClient logs.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.