Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
VijiWaran
New Contributor

SSL VPN on LTE Disconnecting Frequently

We're having trouble with people disconnecting or not being able to connect when using LTE/5G network(Canada's Bell Network). User's hot-spot's via their iPhones and are able to navigate the web but have trouble establishing SSL VPN connection and have issues staying connected.

 

We have the following versions:

Fortigate:7.2.7

FortiEMS:7.2.4

FortiClient: 7.2.4

 

We tried DTLS on and off - no material difference. Maybe the initial connection was easier to establish but nothing life changing. 

 

Auto-reconnect is enabled on Fortigate side but does not really help us in this situation.

 

 Are there anyone who had luck sustaining this type of connection over SSL VPN and are there any particular config anyone has success with?

6 REPLIES 6
adambomb1219
SuperUser
SuperUser

What errors do you see on the FortiClient logs?  What errors do you see on the FortiGate logs?  Windows?  Mac?  Linux?

 

Does Bell use CG-NAT?

VijiWaran
New Contributor

Bell does seemingly use CG-NAT.

 

FGT side we just see that the user has requested termination of service

FortiClient logs show: connection was terminated when no bytes received form other end fro almost 2 minutes

 

 

adambomb1219

Is there a plan you can switch to that doesn't use CG-NAT?  Not sure about Canada but in the US, there are business plans that do not use CG-NAT.

VijiWaran
New Contributor

We'll look at if there is something like that available to us. 

 

For my understanding, why are you suggesting getting off CG-NAT could make our connections better?

adambomb1219

Multiple users connecting to the FortiGate from potentially the same egress IP.  In theory it shouldn't cause any issues but depends on how the CGNAT is deployed.

VijiWaran
New Contributor

Thanks, we'll look into it.

Labels
Top Kudoed Authors