Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
damian_yudha
New Contributor

SSL VPN with fortitoken problem

Hi, 

after upgrading Fortigate 200D from 5.4 to 6.0.3 we have an issue in SSL VPN with fortitoken.

here is the case :

our client uses Forticlient 6.0.1.0099

we defined username with local password, and attached serial number of fortitoken in each username.

when we connect with forticlient, after input the required token, we got error :

 

Unable to logon to the server. Your login credentials not be configured properly (-12) 

 

we tried to change the password with alphanumeric but the result same.

when we revoke the fortitoken from associated username and relogin, the vpn connected.

 

here is the debug :

 

[82:VPN:2de]req: /remote/fortisslvpn [82:VPN:2de]rmt_web_auth_info_parser_common:439 no session id in auth info [82:VPN:2de]rmt_web_access_check:682 access failed, uri=[/remote/fortisslvpn],ret=4103, [82:VPN:2de]req: /remote/login [82:VPN:2de]rmt_web_auth_info_parser_common:439 no session id in auth info [82:VPN:2de]rmt_web_get_access_cache:756 invalid cache, ret=4103 [82:VPN:2dd]sslvpn_read_request_common,682, ret=-1 error=-1, sconn=0x2a9a672800. [82:VPN:2dd]Destroy sconn 0x2a9a672800, connSize=1. (VPN) [82:VPN:2df]allocSSLConn:280 sconn 0x2a9a672800 (6:VPN) [82:VPN:2df]SSL state:before SSL initialization () [82:VPN:2df]SSL state:before SSL initialization () [82:VPN:2df]SSL state:SSLv3/TLS read client hello () [82:VPN:2df]SSL state:SSLv3/TLS write server hello () [82:VPN:2df]SSL state:SSLv3/TLS write change cipher spec () [82:VPN:2df]SSL state:SSLv3/TLS write finished () [82:VPN:2df]SSL state:SSLv3/TLS write finished:system lib() [82:VPN:2df]SSL state:SSLv3/TLS write finished () [82:VPN:2df]SSL state:SSLv3/TLS read change cipher spec () [82:VPN:2df]SSL state:SSLv3/TLS read finished () [82:VPN:2df]SSL state:SSL negotiation finished successfully () [82:VPN:2df]SSL established: TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 [82:VPN:2df]req: /FortiClientSslvpnClearCacheUrl/for/Wini [82:VPN:2df]def: (nil) /FortiClientSslvpnClearCacheUrl/for/WininetLibrary/1/2/3/4/5/6/7/8/9/0/a/b/c/d/e/f/g/h/i/j/k/l/m/n/o/p/q/r/s/t [82:VPN:2de]Timeout for connection 0x2a9a559400.

[82:VPN:2de]Destroy sconn 0x2a9a559400, connSize=1. (VPN) [82:VPN:2df]Timeout for connection 0x2a9a672800.

 

please help, thanks!!

1 REPLY 1
a_ymeri
New Contributor II

I have the same issue,  FortiGate FortiOS 6.0.5 and Forticlient 6.0.4 when Forticlient is installed on windows server 2016 or 2019

 

there is no option on ssl vpn settings to enable sslv3

 

on windows server 2019 the client is trying to connect using tlsv1.3 (this option is not available on fortiOS 6.0.5) 

I am not sure if works on FortiOS 6.2 (I have to plan the upgrade)

 

thanks 

 

 

Labels
Top Kudoed Authors