(now try to establish the SSLVPN connection) ![]() The CLI real-time debugger allows monitoring of the SSLVPN negotiation: ![]() – The Host could not be contacted (no answer to the TCP SYN packet) General debugging of the SSLVPN negotiation Other error messages “Unable to establish the VPN connection. This can probably be solved by reinstalling the FortiClient software on the computer. 98% – hopefully you are not getting stuck at this point… this problem is most likely caused by a corrupted FortiClient installation and/or OS problems.Please doublecheck that you are addressing the correct Realm. Another reason for a failure at 80% is that you are not using the correct Realm. If you are using a remote server you can troubleshoot this communication with the following KB articles: Radius and LDAP. Please check user/usergroup/portal and firewall policy configuration on the FortiGate. 80% – at this stage the username and password is verified.And this KB article explains how to check the TLS versions on a windows client. This KB article describes how to check the TLS versions for SSLVPN on the FortiGate. If the client is using CRL or OCSP make sure that the FortiGate certificate can be checked against those protocols.Īdditionally, it is possible that the TLS versions of Client and FortiGate are not matching. Make sure that this popup window is not hidden behind other windows. In this case the user is shown a popup window to confirm the validity of the certificate. If you are using the default FortiGate certificate, the client is probably not trusting this certificate. 40% – there is an issue with the certificates or the TLS negotiation.Check, if the TLS version that’s in use by the FortiGate is enabled on your client. ![]() If this message is shown, there is a mismatch in the TLS version.
0 Comments
Leave a Reply. |