Description This article describes how to properly set up and
troubleshoot a dial-up VPN with LDAP authentication on Active Directory
and User Certificates provisioned by the Active Directory Certificate
Authority server to endpoints. This can only b...
Description This article analyzes some special cases where 'Signature
verification failed' appears on IKE debug. Scope FortiGate, FortiClient,
3rd party dial up software. Solution A brief explanation of how
signature verification works, after encrypt...
Description This article explains the configuration required for IPsec
dial-up on FortiClient to work with LDAP users. Scope FortiClient,
FortiGate. Solution IKEv2, in contrast to IKEv1, uses EAP for
authentication. When hash-based EAP-MSCHAPv2 (defa...
Description This article analyzes why split split-tunnel MacOS native
dial-up VPN does not work on the default Mac settings. Scope FortiGate,
MacOS. Solution ISAKMP is the protocol used to negotiate the tunnel on
dial-up IPsec. After the first exchan...
Description This article describes why sometimes FortiClient fails to
connect to FortiGate and it returns -5052 or -5053 error codes. Scope
FortiClient, SSL VPN. Solution When establishing an SSL VPN tunnel to
FortiGate, at 89% FortiClient will attem...