Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jumia
New Contributor II

Fortigate as an SSL client not working

I tried to reach out to another #FortiGate through the SSL-VPN client connection but it's not established.

I ran a debug command on the SSL-VPN server to figure out the issue.
I received these logs:

2024-01-16 18:07:19 [260:root:19]allocSSLConn:310 sconn 0x7fab546000 (0:root)
2024-01-16 18:07:21 [260:root:19]SSL state:before SSL initialization (X.X.X.X)
2024-01-16 18:07:21 [260:root:19]SSL state:fatal decode error (X.X.X.X)
2024-01-16 18:07:21 [260:root:19]SSL state:error:(null)(X.X.X.X)
2024-01-16 18:07:21 [260:root:19]SSL_accept failed, 1:unexpected eof while reading
2024-01-16 18:07:21 [260:root:19]Destroy sconn 0x7fab546000, connSize=0. (root)

I used easy-rsa to create a server-client self-signed cert bundle to use for this purpose.

Another thing that I should mention is that whenever I am using "openfortivpn" package in Ubuntu or FortiClient VPN and addressing those self-signed certificate locations for the CA, server cert, and user key, the connection is established without any problem.

I wonder if you have any idea how to sort out this issue.



1 Solution
jumia
New Contributor II

The problem matches a known problem in version 7.4.1 and has already been fixed in 7.4.2.
ID 933985 - FortiGate as SSL VPN client does not work on NP6 and NP6XLite devices.

The issue was resolved after upgrading the firewalls to v7.4.2.

View solution in original post

5 REPLIES 5
AEK
SuperUser
SuperUser

In case the 2 FGTs are different in versions, it is probably due to SSL/TLS negotiation. If this is the case, it may be resolved by aligning SSL versions on both ends, or by updating the lowest FGT.

AEK
AEK
jumia
New Contributor II

@AEK Thanks for the reply.
That wouldn't be the case since both firewalls are in the same version (v7.4.1).
In both firewalls minimum TLS version is 1.2 and the maximum is 1.3.

The same certificate bundle is also uploaded on both. 

 

hbac

Hi @jumia,

 

Is there any firewalls in between which is doing certificate inspection/deep inspection? 

 

Regards, 

jumia
New Contributor II

@hbac 
No, there isn't any firewall in between.

jumia
New Contributor II

The problem matches a known problem in version 7.4.1 and has already been fixed in 7.4.2.
ID 933985 - FortiGate as SSL VPN client does not work on NP6 and NP6XLite devices.

The issue was resolved after upgrading the firewalls to v7.4.2.

Labels
Top Kudoed Authors