- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Cant stablish forticlient VPN remote-access
FortiGate 300E in version 6.2.3 build1066
I'm trying to create an IPsec Tunnel to connect remote to Intranet Servers but don't connect.
I'm doing an IPsec tunnel step by step
1
Start with authentication ( I save the prepared key ) and the group "Bidaidea" has a user called "nacho" with a password that I know
2
Local interface Datos ( 10.10.200.1/24 ) - and I get the client Address Range 10.10.199.50 - 100 ( I tried with 10.10.200.0/24 subnet range )
3
And the VPN and policy are created
4
The policy
Policy created by VPN WIZARD
So if I try an IPSEC connection to de gateway on the same INCOMING interface I configured ( wan1 )
Config on VpnClinet later than the screenshot i changed the gateway
Error trying to connect by VPN
VPN connection failed. Please check your settings, network connection and shared key and try the connection again. If the problem persists contact your network administrator for help.
If I ping the gateway with my PC I get a response, so the gateway is OK.
I tried too with SSL VPN and cant connect.
Otherwise is if I put my credentials wrong, the error message change so Forti come to authenticate me
- Labels:
-
FortiClient
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Nacho,
Please enable debug on the FGT and share the outputs
diag deb reset
diag vpn ike log-filt clear
diag vpn ike log-filt dst-addr4 x.x.x.x <--- Check the public IP on the device and use it here
diag deb appl ike -1
diag deb en
Regards,
Created on ‎06-13-2022 09:54 AM Edited on ‎06-13-2022 09:55 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Dont show anything
I put the commands and tried establish a forticlient connection but nothing show up on the screen
Regards,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Nacho,
I have attached a KB and a cookbook (v6.2.3) here that shows step by step procedure on how to setup ipsec vpn remote-access (Dial Up) . Let me know if this is helpful
https://docs.fortinet.com/document/fortigate/6.2.3/cookbook/785501/forticlient-as-dialup-client
Thank you,
Hope.
