Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BusinessUser
Contributor

The vpn server may be unreachable -14

I have googled as to why this can occur.

My configuration is all correct and i never restrict any hosts.

I am using free forticlient though.

Why cant i go in?

13 REPLIES 13
BusinessUser
Contributor

What are the commands to troubleshoot?

hbac
Staff
Staff

Hi @BusinessUser

 

You can run the following debugs on the FortiGate and try to connect:

# diagnose deb res

# diagnose debug application fnbamd 255
# diagnose debug application sslvpn -1
# diagnose debug console timestamp enable
# diagnose debug enable

 

Run 'di deb dis' to disable the debug.

 

Regards,

FTNT_FortiJan

Hello @BusinessUser,

 

Please verify your SSL VPN configuration to see whether "Host Check" option is enabled.

 

See following KB article for more details:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-VPN-Server-may-be-unreachable-14/ta-p/2038...

 

Best regards,

FortiJan
sundar33w
New Contributor

You can run the following debugs on the FortiGate and try to connect:

 

mpeddalla
Staff
Staff

Hello Businessuser,

 

Thank you for reaching the Fortinet support forum.

Please confirm did you have time to verify the commands and try connecting to ssl vpn ?

-Can you please confirm the below information as well:

1. What is the free version for forticlient and also the Fortigate firmware version?

2. are you using local user authentication or else LDAP /RAIDUS /FSSO /SAML to connect ssl vpn ?

3. At what percentage does the error come up?

4. How many users are affected by this issue?

 

debugs you can use : 

 

#diag deb reset

#diag deb console timestamp enable

#diag vpn ssl debug-filter src-addr4 x.x.x.x      (where x.x.x.x is the public ip address of the user from where the vpn is initiated)

#diag debug app sslvpn -1

#diag debug app fnbamd -1

#diag deb en

 

diag de disable ----to stop debugs 

 

article can help further :

 

Troubleshooting Tip: SSL VPN Troubleshooting - Fortinet Community

 

Regards,

Manasa

 

BusinessUser

 

1. What is the free version for forticlient and also the Fortigate firmware version?

7.0.9.0493 for the forticlient vpn. v7.0.18 build 0450 for FW.

 

2. are you using local user authentication or else LDAP /RAIDUS /FSSO /SAML to connect ssl vpn ?

I am using local authentication.

3. At what percentage does the error come up?

It comes up at 80%

4. How many users are affected by this issue?

This is a new setup and I am currently testing with 1 user - myself.

 

I can ping the wan interface. However, no logs are appearing after issuing the debug coommands. It doesnt even hit the FW rules. I have no idea what is the issue.

js2

Hi Business User,

 

It seems to be an issue with Forticlient version. As you are running free Forticlient version check with FortiClient version 6.0.

 

Refer on this below article:

 

https://community.fortinet.com/t5/FortiClient/Technical-Tip-FortiClient-SSLVPN-gets-struck-at-80/ta-...

 

Regards,

Joshi 

BusinessUser

Downgrading the forticlient works.

But shouldn't a later version be better than the old one?

mpeddalla

Thank you for the update,

 

-For testing purposes can you try enabling web mode and verify if you can log in to the firewall so that we can at least verify if it is forticlient issue or a firewall issue?

-If you are able to login from web mode then we can try changing forticlient version.

-If the error comes at 80% then authentication is reaching firewall but might having issue with firewall policy we can check further 

Troubleshooting Tip: Possible reasons for FortiCli... - Fortinet Community

 

Regards,

Manasa

 

 

Labels
Top Kudoed Authors