Hot!SSL VPN with fortitoken problem

New Member
  • Total Posts : 1
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/11/28 19:07:28
  • Status: offline
2018/11/28 19:19:12 (permalink)

SSL VPN with fortitoken problem

after upgrading Fortigate 200D from 5.4 to 6.0.3 we have an issue in SSL VPN with fortitoken.
here is the case :
our client uses Forticlient
we defined username with local password, and attached serial number of fortitoken in each username.
when we connect with forticlient, after input the required token, we got error :
Unable to logon to the server. Your login credentials not be configured properly (-12) 
we tried to change the password with alphanumeric but the result same.
when we revoke the fortitoken from associated username and relogin, the vpn connected.
here is the debug :
[82:VPN:2de]req: /remote/fortisslvpn
[82:VPN:2de]rmt_web_auth_info_parser_common:439 no session id in auth info
[82:VPN:2de]rmt_web_access_check:682 access failed, uri=[/remote/fortisslvpn],ret=4103,
[82:VPN:2de]req: /remote/login
[82:VPN:2de]rmt_web_auth_info_parser_common:439 no session id in auth info
[82:VPN:2de]rmt_web_get_access_cache:756 invalid cache, ret=4103
[82:VPN:2dd]sslvpn_read_request_common,682, ret=-1 error=-1, sconn=0x2a9a672800.
[82:VPN:2dd]Destroy sconn 0x2a9a672800, connSize=1. (VPN)
[82:VPN:2df]allocSSLConn:280 sconn 0x2a9a672800 (6:VPN)
[82:VPN:2df]SSL state:before SSL initialization ()
[82:VPN:2df]SSL state:before SSL initialization ()
[82:VPN:2df]SSL state:SSLv3/TLS read client hello ()
[82:VPN:2df]SSL state:SSLv3/TLS write server hello ()
[82:VPN:2df]SSL state:SSLv3/TLS write change cipher spec ()
[82:VPN:2df]SSL state:SSLv3/TLS write finished ()
[82:VPN:2df]SSL state:SSLv3/TLS write finished:system lib()
[82:VPN:2df]SSL state:SSLv3/TLS write finished ()
[82:VPN:2df]SSL state:SSLv3/TLS read change cipher spec ()
[82:VPN:2df]SSL state:SSLv3/TLS read finished ()
[82:VPN:2df]SSL state:SSL negotiation finished successfully ()
[82:VPN:2df]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384
[82:VPN:2df]req: /FortiClientSslvpnClearCacheUrl/for/Wini
[82:VPN:2df]def: (nil) /FortiClientSslvpnClearCacheUrl/for/WininetLibrary/1/2/3/4/5/6/7/8/9/0/a/b/c/d/e/f/g/h/i/j/k/l/m/n/o/p/q/r/s/t
[82:VPN:2de]Timeout for connection 0x2a9a559400.
[82:VPN:2de]Destroy sconn 0x2a9a559400, connSize=1. (VPN)
[82:VPN:2df]Timeout for connection 0x2a9a672800.
please help, thanks!!

1 Reply Related Threads

    New Member
    • Total Posts : 4
    • Scores: 0
    • Reward points: 0
    • Joined: 2017/03/07 08:20:22
    • Location: Tirana, Albania
    • Status: offline
    Re: SSL VPN with fortitoken problem 2019/10/14 05:20:52 (permalink)
    I have the same issue,  FortiGate FortiOS 6.0.5 and Forticlient 6.0.4 when Forticlient is installed on windows server 2016 or 2019
    there is no option on ssl vpn settings to enable sslv3
    on windows server 2019 the client is trying to connect using tlsv1.3 (this option is not available on fortiOS 6.0.5) 
    I am not sure if works on FortiOS 6.2 (I have to plan the upgrade)
    Jump to:
    © 2020 APG vNext Commercial Version 5.5