Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
munk
New Contributor

FortiClient does not work with D-Link GO-RT-AC750 router

I have got FortiClient to connect to my enterprise VPN, but I can not connect through my router. The error message is: VPN has "trouble connecting with the remote gateway, retrying now..." The connection through a mobile phone net is successful. Are there any settings, I should do on the router?

Thanks

1 Solution
SteveG
Contributor III

I'd expect SPI would need to be enabled for the ALG settings to work. If you're still having problems I'd do two things next.

 

1, Take a look at the VPN logs on the FortiGate that's terminating the VPN as that often gives a pointer.

2, run a Diag sniff packet any 'host x.x.x.x' on the Fortigate (replace the x.x.x.x with the public IP of the D-Link). You should see the IPSec phase 1 traffic (UDP 500/4500) then the actual encrypted payload (phase 2 - protocol 50). If you don't see protocol 50 arriving on the FG then the D-Link is dropping it.

View solution in original post

4 REPLIES 4
SteveG
Contributor III

You normally need to enable IPSec support on routers. Have you enabled IPSec ALG (page 85 in the manual).

 

https://eu.dlink.com/cz/c...b1_manual_v2_00_eu.pdf

munk
New Contributor

Dear Steve,

thanks for the reply, but the IPSec is enabled, and the connection fails. Any other suggestions?

Sandor Munk

SteveG
Contributor III

I'd expect SPI would need to be enabled for the ALG settings to work. If you're still having problems I'd do two things next.

 

1, Take a look at the VPN logs on the FortiGate that's terminating the VPN as that often gives a pointer.

2, run a Diag sniff packet any 'host x.x.x.x' on the Fortigate (replace the x.x.x.x with the public IP of the D-Link). You should see the IPSec phase 1 traffic (UDP 500/4500) then the actual encrypted payload (phase 2 - protocol 50). If you don't see protocol 50 arriving on the FG then the D-Link is dropping it.

munk
New Contributor

Dear Steve,

I actually cannot reach the VPN IT guys. Have You any suggestion, what should I do, what should I set in configuration, if the D-Link GO-RT-AC750 router drops IPSec UDP packets?

Sandor MUNK

Labels
Top Kudoed Authors