Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rlewcosa
New Contributor

FortiClient VPN Connect/Immediate Disconnect

I have seen a few posts with the same title but nobody seems to have found a solution yet. Has anyone found a working solution to the issue where FortiClient will connect to VPN then immediately disconnect? We are using FortiClient with EMS, and if the user has auto retry checked it will repeatedly try to reconnect and fail. Sometimes I can force it to start working again by shutting down the Forticlient app and restarting the computer but I can't find any useful information in logs or debug info. FG is on 7.4.2, FC client is 7.2.3, and EMS 7.2.2 (which I plan to update to 7.2.4 sometime this week).  If you have any solutions I appreciate it!

6 REPLIES 6
xshkurti
Staff
Staff

@rlewcosa 
Can you please check if there is any other software installed on your machine that might conflict with FortiClient? Some other VPN solution?

rlewcosa

I can confirm there is no other VPN software, we had previously been using the free Forticlient before upgrading to the full ZTNA version with EMS/FortiAuth. This is occurring however on both devices that had been upgraded and new, fresh Windows installs.

johnathan
Staff
Staff

Do you see it successfully establish (screen changes, gives you an IP), or does it stop at a specific percentage (98%)? Are you using SAML?
In cases like these, I like to disable IPv6 on both your physical Ethernet adaptor, and the Fortinet SSLVPN adaptor as well.

rlewcosa

It does successfully establish - User will hit connect, it reaches 48% and prompts for their token key which they enter, then pauses for a second at 98%. After that it will say connected successfully followed immediately by a disconnected message. When it does that they usually are not successful trying to connect again, they have to shutdown the client and reboot. I'll try disabling the IPv6 and see what happens.

 

I am wondering if latency could be causing it? The devices are laptops in police cars running almost 100% off of cellular. While we generally have good reception and average around 50mbps off LTE, I'm wondering if any bit of latency causes issues with the connection process. I do have an email out with our account rep so if I find out anything useful I'll update the thread.

 

**Edit: I should add, when viewing the authentication logs in FortiAuthenticator for the affected user, it will show multiple "login successful, awaiting token" and "token successful" entries back to back, no error messages or failures.

johnathan

Hmmm, I would also try with and without DTLS if you know latency is gonna be high. I have had similar cases where DTLS would refuse to work, and others where it would only work with DTLS on. 

rlewcosa

I'll try that and see what happens. DTLS is currently off but I'll enable it and listen for any end users having problems.

Labels
Top Kudoed Authors