Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
GTA_doum
New Contributor

SSLVPN with XP

Hello,

I want old connection type to work with the SSLVPN connection of my FortiGate 80C router, with firmware 5.6.3.  I found how to activate tlsv1-0 in the SSLVPN, so the FortiClient gets passed the connection credentials, but stops after and returns permission denied.  From the SSLVPN web page also, same error from IE 8 after logging in.

I guess tlsv1-0 needs to be allowed somewhere else also.  What and where do I modify settings to let Windows XP connect to SSLVPN on this newer firmware?

Thanks.

4 REPLIES 4
LuisMLG
New Contributor

Why not disable the TLS-v1 in your XP and force it to use the new TLS.

emnoc
Esteemed Contributor III

I found how to activate tlsv1-0 in the SSLVPN, so the FortiClient gets passed the connection credentials, but stops after and returns permission denied

 

Why do you think its tLS v1.0. You state it get's pass  credentials  so that means something is happening.

 

run diag debug commands and investigate

 

 

diag debug enable

diag debug application  sslvpn -1

 

Your long term should be to look at a newer OS. Forticlient ( latest versions ) are not supported on XP and XP should be eliminated by now ( yes I know many are still out on it ). But in reality   MS has a low cost to free upgrade from XP.

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
GTA_doum
New Contributor

That computer will eventually get updated to a newer OS, but for now, I need it to connect like it used to.  Since it was working fine with previous ForitOS, it can work again.  Newer FortiOS disables TLSv1-0, and I found how to reactivate it for SSL-VPN, which is why I can pass credentials now.  I guess it needs to be reactivated elsewhere to get through the "permission denied" security block.

I will try the diag debug...

GTA_doum

Newer TLS are not available with XP.

Labels
Top Kudoed Authors