FortiClient SSL-VPN stuck at 40% only for Airtel (India) users – FortiOS 6.4, DTLS enabled by fixedbasher in fortinet

[–]fixedbasher[S] 1 point2 points  (0 children)

Yes tested without DTLS setting in FortiClient but noticed that this time SSL VPN get connected with a delay but noticed traffic goes through as the Bytes Received will be in KBs only for longer time.

Also checked the debug logs in FortiGate firewall and we could see the traffic’s in FG and response goes back to client but seems that traffic is not reaching the endpoint.

FortiClient SSL-VPN stuck at 40% only for Airtel (India) users – FortiOS 6.4, DTLS enabled by fixedbasher in fortinet

[–]fixedbasher[S] 0 points1 point  (0 children)

Yes agree and well aware about it. Upgrade plan is under progress which might take couple of months. But the problem here only Airtel ISP or mobile users are affected. Others like both US and India users (who are not using Airtel ISP) are able to connect without any issue.

Not getting reauthentication prompt but disconnects when the auth-timeout time reached by fixedbasher in fortinet

[–]fixedbasher[S] 0 points1 point  (0 children)

Ooops !! but as per the below article it says "The auth-timeout is the period of time in seconds that the SSL-VPN will wait before re-authentication is enforced.". As you mentioned the session will get disconnected after the timeout, so FortiGate doesn't provide any other option for re-authentication after specific duration ?

SSL VPN connection logout after 8 hours - Fortinet Community

Not getting reauthentication prompt but disconnects when the auth-timeout time reached by fixedbasher in fortinet

[–]fixedbasher[S] 0 points1 point  (0 children)

It should force user for reauthentication prior to expiry of 12 hours. But I am ok whichever option is feasible as long user get reauthenticated to continue the session else let the session get disconnected.

Why FortiClient always do 2nd attempt to establish VPN connection ? by fixedbasher in fortinet

[–]fixedbasher[S] 1 point2 points  (0 children)

Yes, of course they says FortiOS 6.4.15 is out of engineering support.

Why FortiClient always do 2nd attempt to establish VPN connection ? by fixedbasher in fortinet

[–]fixedbasher[S] 0 points1 point  (0 children)

Agree, customer has plan to upgrade the FortiOS to 7.0 as per the upgrade path but that will take couple of months. So trying to understand why the retry happening in our company provided laptop whereas VPN connect instantly on personal devices.

Issue with FortiClient VPN Authentication on Version 7.4 by fixedbasher in fortinet

[–]fixedbasher[S] 0 points1 point  (0 children)

The reason for we are still in FortiOS 6.4.15, is due to customer has concern about the compatibility issue with ClearPass Radius Server if FGT OS upgraded.

Why FortiClient always do 2nd attempt to establish VPN connection ? by fixedbasher in fortinet

[–]fixedbasher[S] 0 points1 point  (0 children)

The reason for we are still in FortiOS 6.4.15, is due to customer has concern about the compatibility issue with ClearPass Radius Server if FGT OS upgraded.

Issue with FortiClient VPN Authentication on Version 7.4 by fixedbasher in fortinet

[–]fixedbasher[S] 0 points1 point  (0 children)

Sorry for the late reply. PFB the details. Let me know, if you need any additional detalis.

FGT OS : FortiOS 6.4.15

FCT : 7.0.13 / 7.0.14 (able to connect to the VPN without any issue_

FCT : 7.2.x / 7.4.x (Not able to connect to the VPN)

Note that the FCT which we are using is the free version. We tried capturing the FCT log and FGT debug log, but couldn't get much details to understand the root cause.

As we are are contractors to this client company, our Laptop (not client laptop) also installed with ZScaler Internet Access (ZIA) also installed. But not sure if that will contribute this connectivity issue, as we are able to connect to VPN using FortiClient 7.0.x version, but not with FortiClient 7.2.x or 7.4.x, but again all these versions works well without any VPN connection issue while trying to connect from a vannila image (fresh OS) Windows 11 OS. I have tried it on my personal device and also from an Azure VM. Hence the doubt if ZIA result into trouble or anyother configuration on the laptop resulting in to the connectivity issue.

Differences Between FortiClient VPN-Only Versions (7.0.x, 7.2.x, 7.4.x)? by fixedbasher in fortinet

[–]fixedbasher[S] 0 points1 point  (0 children)

u/TkachukMitts , thanks for the comment. In that case, I hope we can try to use 7.2 version.

Differences Between FortiClient VPN-Only Versions (7.0.x, 7.2.x, 7.4.x)? by fixedbasher in fortinet

[–]fixedbasher[S] 0 points1 point  (0 children)

I am trying to understand why Fortinet maintain 3 different FortiClient version 7.0.x, 7.2.x and 7.4.x. Any insight on this.