Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nyagi
New Contributor

FortiTray error: stuck at connecting on MacOS for specific users

I am having problems with two user accounts that are unable to connect to an SSL VPN using Forticlient on MacOS devices. These users are able to successfully connect on Windows devices. No other org users are currently reporting this issue. The users have Ventura and Sonoma, and we have a Macbook for testing running Monterey. We have tested 7.0.9, 7.2.2, and 7.2.3 and the issue happens to these users only. I am able to successfully sign in on their devices and our test device.

 

After entering the 2fa token, the client is stuck at connecting. Fortigate shows a successful authentication, but nothing happens on the client side.

The logs seem to show a FortiTray error, but I am able to connect using my account on their device.

 

Below is a portion of the log that I found where the users seem to be having problems: 

20240212 09:39:50 TZ=-1000 [FortiTray:DEBG] vpnconnection.mm:759 Cancel http. http task is running: Yes
20240212 09:39:50 TZ=-1000 [FortiTray:DEBG] vpnconnection.mm:549 Request: [POST] "/remote/logincheck"
20240212 09:39:50 TZ=-1000 [FortiTray:INFO] HttpsNWConnection.swift:134 Connection cancelled
20240212 09:39:50 TZ=-1000 [FortiTray:EROR] vpnconnection.mm:692 POSIXErrorCode: Operation canceled
20240212 09:39:50 TZ=-1000 [FortiTray:EROR] vpnconnection.mm:729 Stop on error: Can not connect to VPN server.
20240212 09:39:50 TZ=-1000 [FortiTray:DEBG] vpnconnection.mm:713 Stop process.
20240212 09:39:50 TZ=-1000 [FortiTray:DEBG] vpnconnection.mm:759 Cancel http. http task is running: No
20240212 09:39:50 TZ=-1000 [FortiTray:INFO] VpnManager.swift:2927 Notification: Cancel input
20240212 09:39:50 TZ=-1000 [FortiTray:INFO] sslvpn_bridge.mm:206 VPN login exception: [1] Can not connect to VPN server.
20240212 09:39:50 TZ=-1000 [FortiTray:INFO] VpnManager.swift:2736 Notification: Login network error. Can not connect to VPN server.
20240212 09:39:50 TZ=-1000 [FortiTray:INFO] VpnManager.swift:936 No retry on manual connect
20240212 09:39:50 TZ=-1000 [FortiTray:DEBG] VpnManager.swift:951 On VPN status change: Connecting -> DisconnectedBecauseOfError("Network error. Can not connect to VPN server.", true, FortiTray.VpnStatus.DisconnectedErrorType.CommonError)
20240212 09:39:50 TZ=-1000 [FortiTray:INFO] VpnManager.swift:961 VPN disconnected because of error: Network error. Can not connect to VPN server.
20240212 09:39:50 TZ=-1000 [FortiTray:DEBG] VpnManager.swift:813 On VPN session end
20240212 09:39:50 TZ=-1000 [FortiTray:DEBG] VpnManager.swift:852 Waiting for VPN session to end
20240212 09:39:50 TZ=-1000 [FortiTray:DEBG] sslvpn_bridge.mm:598 VPN session wait until finished
20240212 09:39:50 TZ=-1000 [FortiTray:DEBG] VpnManager.swift:854 VPN session ended
20240212 09:39:50 TZ=-1000 [FortiTray:DEBG] VpnManager.swift:863 On VPN disconnected

 

Here is the same portion from my sucessful login on the same Mac 2 minutes prior(IPs removed for privacy):

20240212 09:37:07 TZ=-1000 [FortiTray:DEBG] vpnconnection.mm:549 Request: [GET] "/remote/login"
20240212 09:37:07 TZ=-1000 [FortiTray:DEBG] HttpsNWConnection.swift:130 Connected to *vpn ip*
20240212 09:37:07 TZ=-1000 [FortiTray:INFO] sslvpn.cpp:332 Send authentication request
20240212 09:37:07 TZ=-1000 [FortiTray:DEBG] vpnconnection.mm:549 Request: [POST] "/remote/logincheck"
20240212 09:37:07 TZ=-1000 [FortiTray:DEBG] HttpsNWConnection.swift:130 Connected to *vpn ip*
20240212 09:37:07 TZ=-1000 [FortiTray:INFO] sslvpn.cpp:396 Check response
20240212 09:37:07 TZ=-1000 [FortiTray:DEBG] sslvpn.cpp:420 Server requires FortiToken. Token info: ftm_push
20240212 09:37:07 TZ=-1000 [FortiTray:DEBG] sslvpn.cpp:478 Auto FTM Push
20240212 09:37:07 TZ=-1000 [FortiTray:DEBG] vpnconnection.mm:549 Request: [POST] "/remote/logincheck"
20240212 09:37:07 TZ=-1000 [FortiTray:INFO] VpnManager.swift:2843 Input request type: 1
20240212 09:37:08 TZ=-1000 [FortiTray:DEBG] HttpsNWConnection.swift:130 Connected to *vpn ip*
20240212 09:37:16 TZ=-1000 [FortiTray:INFO] VpnManager.swift:2927 Notification: Cancel input
20240212 09:37:16 TZ=-1000 [FortiTray:INFO] sslvpn.cpp:529 Authentication passed
20240212 09:37:16 TZ=-1000 [FortiTray:DEBG] vpnconnection.mm:549 Request (non-essential): [GET] "/remote/fortisslvpn"
20240212 09:37:16 TZ=-1000 [FortiTray:DEBG] HttpsNWConnection.swift:130 Connected to *vpn ip*
20240212 09:37:16 TZ=-1000 [FortiTray:DEBG] vpnconnection.mm:549 Request: [GET] "/remote/fortisslvpn_xml"
20240212 09:37:16 TZ=-1000 [FortiTray:DEBG] HttpsNWConnection.swift:130 Connected to *vpn ip*
20240212 09:37:16 TZ=-1000 [FortiTray:DEBG] vpnconnection.mm:713 Stop process.

 

I have tried uninstalling and reinstalling multiple times with no resolution. I have allowed the FortiTray on install but don't currently see it anywhere in the privacy settings. I am able to connect on these devices so I'm not sure what the problem is.

 

Any information regarding this error is greatly appreciated.

2 REPLIES 2
asaiah9
New Contributor

The newest version of MacOS requires you accept 3rd party kernel extensions. GlobalProtect is one such application that requires it. Go to system preferences > security. You may have a button to allow GP on the bottom of that window https://mobdro.bio/

nyagi
New Contributor

Thanks for your reply.

Is there any way to trigger the prompts? I temporarily set my test Macbook to no security in the system utilities and did a reinstall of FortiClient. I get the notification to allow FortiTray, but no difference in security & privacy.

I can still connect, but our affected users are out of office today so I'm waiting for them to come back.

Also wondering if this would somehow be specific to the FortiClient account as I'm still able to sign in on their Mac device.

Labels
Top Kudoed Authors