Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
smecio
New Contributor II

FortiClientVPN 7.x is not working properly on iMac Late 2013 Catalina

Install & configure step by step:

  1. Install FortiClient VPN 7.x (7.0.9 and 7.2.4) onto macOS Catal
  2. Allow fctservctl2 and FortiClient with Full Disk Access permission in Security & Privacy
  3. Launch FortiClient for the first time and accept the terms
  4. Add a new IPSec VPN profile
  5. Enter username and password
  6. Connect

The dashboard show status "VPN Connected" but there is no connection actually. On the other hand, the version 6.4.9 works perfectly. Any idea that it is a bug or FortiClient 7 has dropped support for Catalina?

2 Solutions
smecio
New Contributor II

There are a number of active connections to the mentioned remote access VPN at all times so that it's hard to execute the diagnosis without distraction.

 

On the iMac 2013 27" Late 2013, I have tried to:

  1. Uninstall FortiClient VPN 6.4.9
  2. Install FortiClient VPN 7.2.4
  3. Set up the IPSec VPN for the remote access
  4. Check the FortiClient Console:
    • Status → `VPN connected`
    • Execute `netstat -rn` → There exist route entries
  5. Check the actual connection → FAILED
  6. Uninstall FortiClient VPN 7.2.4
  7. Install FortiClient VPN 7.0.9
  8. Set up the IPSec VPN for the remote access
  9. Check the FortiClient Console:
    • Status → `VPN connected`
    • Execute `netstat -rn` → There exist route entries
  10. Check the actual connection → FAILED
  11. Uninstall FortiClient VPN 7.0.9
  12. Install FortiClient VPN 6.4.9
  13. Set up the IPSec VPN for the remote access
  14. Check the FortiClient Console:
    • Status → `VPN connected`
    • Execute `netstat -rn` → There exist route entries
  15. Check the actual connection → SUCCESS

macOS Catalina (11.15.7) is pretty old and out of date, so it is not a big deal for me. Since there is no official announcement that FortiClient 7.x shall not be working properly on it, I would like to veriry and be confirmed about that.

View solution in original post

dbu

Thanks for the description. 

It looks like even with branch 7.0 is not working. 

I did a quick search and could not find any documentation to support the same. 
Perhaps you need to stay with 6.4.9 if possible. 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.

View solution in original post

4 REPLIES 4
sahmed_FTNT
Staff
Staff

Hello, I would suggest collecting IPSEC debug logs for further review

Security all we want
dbu
Staff
Staff

@smecio ,
We need to understand more about this connection attempt.
Enable mentioned ipsec debug:
diag debug app ike -1
diag debug console timestamp enable
diag debug enable
Try to connect and check the output for any possible error. 

 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
smecio
New Contributor II

There are a number of active connections to the mentioned remote access VPN at all times so that it's hard to execute the diagnosis without distraction.

 

On the iMac 2013 27" Late 2013, I have tried to:

  1. Uninstall FortiClient VPN 6.4.9
  2. Install FortiClient VPN 7.2.4
  3. Set up the IPSec VPN for the remote access
  4. Check the FortiClient Console:
    • Status → `VPN connected`
    • Execute `netstat -rn` → There exist route entries
  5. Check the actual connection → FAILED
  6. Uninstall FortiClient VPN 7.2.4
  7. Install FortiClient VPN 7.0.9
  8. Set up the IPSec VPN for the remote access
  9. Check the FortiClient Console:
    • Status → `VPN connected`
    • Execute `netstat -rn` → There exist route entries
  10. Check the actual connection → FAILED
  11. Uninstall FortiClient VPN 7.0.9
  12. Install FortiClient VPN 6.4.9
  13. Set up the IPSec VPN for the remote access
  14. Check the FortiClient Console:
    • Status → `VPN connected`
    • Execute `netstat -rn` → There exist route entries
  15. Check the actual connection → SUCCESS

macOS Catalina (11.15.7) is pretty old and out of date, so it is not a big deal for me. Since there is no official announcement that FortiClient 7.x shall not be working properly on it, I would like to veriry and be confirmed about that.

dbu

Thanks for the description. 

It looks like even with branch 7.0 is not working. 

I did a quick search and could not find any documentation to support the same. 
Perhaps you need to stay with 6.4.9 if possible. 

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
Labels
Top Kudoed Authors