Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
papapuff
New Contributor II

VPN SSL - Error -455

hi there,

 

need help please.

we use fg60d and fg30e. all with firmware 5.6.2

 

after upgrade fortios, clients can't vpnssl from their computer.

version forticlient 5.6.6 ; antivirus kaspersky, windows 7 sp1.

complete error message is:

--------------------------- Warning --------------------------- Your PC does not meet the host checking requirements set by the firewall. Please check that your OS version or antivirus and firewall applications are installed and running properly or you have the right network interface.  (-455) --------------------------- OK    ---------------------------

but I can connect vpnssl using my moble phone (android based).

 

any advice?

thanks in advance.

11 REPLIES 11
Toshi_Esumi
SuperUser
SuperUser

Are they local users? Or RADIUS/TACACS/LDAP users who are authenticated by outside servers? If local, you might have lost password after the upgrade. I heard about an 5.6 upgrade issue that might wipe out all vpn PSK passwords. It might happened to local user passwords.

papapuff

Hi, Yes they are local user. Then the solution is just delete that user and create one? Or else?
Toshi_Esumi

First you need to check if it's still there or not with "show user local". Then if they're gone, copy and paste the password statement (with ENC password) from your backup config file.

papapuff

hi,

have tried to change password, create new user.

still same, the error message msg="SSLVPN tunnel connection failed (Error=-455).

 

when first install forticlient 5.6.6, got same error message. so after I update my windows. try connect and it's works.

 

now when I want to connect again, it shown that error. windows has latest update, so do with antivirus.

 

papapuff
New Contributor II

tried everything...but can't work...

 

just amaze with new forticlient...why this happen..

Toshi_Esumi

You can try multiple things but likely need to open a TAC case with the FortiGate.

Those things are:

- sslvpn app debugging at FG (diag debug app sslvpn -1)

- FortiClient local log (set "debug" level and take all VPN log)

- downgrade FC5.6.6 to something lowler, like 5.6.0, 5.6.1, ...

Probably you don't want to downgrade FG itself to the previous version.

Toshi_Esumi

One more thing: Since any SSL VPNs don't seem to work any more, make sure you didn't lose SSL VPN config itself during the upgrade: settings, portals, and policies w/ the user group(s).

daniel_azeredo

Hi, I have also had a similar issue and I solved by changed some configuration in internet explore. go to internet explorer, settings, internet options, advanced and checkbox all TLS version.

Toshi_Esumi

It was right at the screen in the original post. I read it in email, which was truncated, and didn't read the entire post when I responded. The new version likely allow only higher TLS levels. You can reenable disabled one with "set slsv1-0 enable" and so on under "config vpn ssl settings" but raising the capability on the client side like Daniel did is the right way.

Labels
Top Kudoed Authors