Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bluetech
New Contributor

EC2 instance RDP connection disconnects when I use ZTNA

I'm a contractor trying to connect to a client's Forticlient VPN gateway from my Windows EC2 instance. To do this, I was instructed to download Forticlient ZTNA, and I was given an EMS Server URL.  

 

1. I connect to my Windows instance via RDP

1. I download Forticlient ZTNA on the Windows EC2 instance

2. I put in the EMS URL, which successfully connects 

3. I click on Remote Access and type in a username and password for the VPN.  When I do this, I get disconnected from the EC2 instance.  Important note: I get disconnected even if I purposefully type in an incorrect password.  In other words, I'm not even successfully connecting to the VPN, but something about the attempt to connect to the VPN causes RDP to disconnect. 

I've also tried using TeamViewer instead of RDP and the same issue occurs.  

 

Can anyone help me with this?  

4 REPLIES 4
rtanagras
Staff
Staff

Hi @bluetech - It's good to troubleshoot this with our EMS Team. Have you allowed the necessary ports in your AWS Security Groups for RDP?

 

Is your setup also using split tunneling? Try adding another interface to your instance and assign an EIP so you can still remote into it while connecting with FortiClient.

Best,
Ricky
bluetech

Great suggestion on additional interface, will give this a shot as well

 

hbac
Staff
Staff

Hi @bluetech,

 

Are you referring to IPsec VPN? If yes, you need to set <implied_SPDO> to and set  <implied_SPDO_timeout> greater then 0. FortiClient allows all outbound traffic (including non-IKE traffic) for the duration configured. Some users find that a value of 30 or 60 seconds suffices. Please refer to https://docs.fortinet.com/document/forticlient/7.2.4/xml-reference-guide/96295/ike-settings

 

Regards,

bluetech
New Contributor

This seems promising, I'll give this a shot.  

Labels
Top Kudoed Authors