Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ArnaudL
New Contributor

VPNSSL connection almost impossible, reset at 98%

Hi all !

 

Latest version of FortiClient VPN (7.0.11.0569), latest FGT firmware (v7.0.14 build0601)

I am using a Windows 11 insider dev channel. Since last weeks upgrade (build 26058 release 240209-1555), I am almost unable to connect via SSLVPN.

Nothing has changed appart from this upgrade, all the other remote users running "standard" windows 11 versions have absolutely no problem.

 

My client log is filled with errors that I found on other threads but with no solution :

error: poll_send_ssl ->SSL_get_error(): 5, try:1
error: poll_send_ssl -> WSAGetLastError():2745, try:1
error: poll_send_ssl ->data size: 66, try:1
[handle_driver_read_event]: error: poll_send
error: poll_recv_ssl -> SSL_get_error(): 5
error: poll_recv_ssl -> WSAGetLastError():2745
error: polling recv, try:1

etc....

 

If I insist a lot, after some time it will connect (maybe 20 retries), and the log looks absolutely normal (nothing logged appart from connection established).

 

On the Fortigate side, I have "SSL web application blocked", and "ssl exit error, reason DH Lib".
I have no idea what this is, and above all why it sometimes work !

 

Can some help me on this matter ? Thanks a lot !

 

PS : there is not client certificate, as some support pages mention this.

11 REPLIES 11
ArnaudL
New Contributor

Hi @hbac 

I am on a corporate computer, so my configuration is the same as all the other workstations (same hardware, same security software).

I am the only one having this problem, but as I already mentionned I am also the only one running windows 11 insider preview dev channel.
This occurred right after the latest insider preview upgrade. In fact maybe not the latest but the one mentioned in my original post.

 

I'm quite confident the problem came with this upgrade, so this would be an OS/Forticlient compatibility issue. I have no way to be sure of this, this is just the way the problem arose suddenly and the fact that I am the only one with this problem that makes it obvious to me.

ArnaudL
New Contributor

Update
It is still a nightmare to connect (I have to try for sometimes 30 minutes), but I found out that disconnecting and reconnecting my wifi sometimes helps. It does not always work but after a dis/reconnection I definitively have a higher success rate.
Please note that my personal computer, on the same network, has no problem at all connection to this sslvpn endpoint. Not the same windows version, obviously.

Labels
Top Kudoed Authors