{"id":1481,"date":"2021-05-03T14:44:52","date_gmt":"2021-05-03T18:44:52","guid":{"rendered":"https:\/\/increasec.com\/?p=1481"},"modified":"2023-05-18T09:52:05","modified_gmt":"2023-05-18T13:52:05","slug":"fortinet-vpn-troubleshooting","status":"publish","type":"post","link":"https:\/\/increasec.com\/?p=1481","title":{"rendered":"Fortinet VPN basic troubleshooting"},"content":{"rendered":"\n<p>Here are the troubleshooting steps i use<\/p>\n\n\n\n<p>1 sign on to the user PC using TeamViewer\/Splashtop or similar<\/p>\n\n\n\n<p>2 verify client is correct version.   v7.0 is available now, Fortinet has re-arranged their website, there are multiple products all named similarly.  Lots of confusion here.   If in doubt, re-install.<\/p>\n\n\n\n<p>3 verify settings are correct in the client<\/p>\n\n\n\n<p>4 attempt a connection while looking at the Firewall web interface, VPN, IPsec tunnels, under status click # dialup connections<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"861\" height=\"144\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/05\/image-2.png\" alt=\"\" class=\"wp-image-1484\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/05\/image-2.png 861w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/05\/image-2-300x50.png 300w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/05\/image-2-768x128.png 768w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/05\/image-2-710x119.png 710w\" sizes=\"auto, (max-width: 861px) 100vw, 861px\" \/><\/figure>\n\n\n\n<p>5. hover over connections until you find the user in question.  This makes sure you are connecting to the firewall you expect.  The client could be connecting to a VPN tunnel you are not expecting  ie the iOS VPN tunnel which doesn&#8217;t have permissions to get to where the user wants to go.   But usually if the phase1 negotiation selects the wrong connector it just fails.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"625\" height=\"338\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/05\/image-3.png\" alt=\"\" class=\"wp-image-1485\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2021\/05\/image-3.png 625w, https:\/\/increasec.com\/wp-content\/uploads\/2021\/05\/image-3-300x162.png 300w\" sizes=\"auto, (max-width: 625px) 100vw, 625px\" \/><\/figure>\n\n\n\n<p>Next try and do a ping to the inside interface of the firewall.  If you cannot that is a good indication that the problem is either routing or protocols on the client end.<\/p>\n\n\n\n<p>Disable IPv6 if it is enabled<\/p>\n\n\n\n<p>Disable any non-Microsoft Firewall product<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>IF this is a NEW VPN connection:<br>Lookup the external address on your firewall and don&#8217;t use tools like http:\/\/whatsmyip.org  <br>they report the closest public IP to you, which isn&#8217;t always the IP of your firewall.<br>Double NAT is a problem where your firewall does NAT but so does the ISP provided, upstream hardware that your firewall is plugged into.<br>The normal solution is to put the ISP hardware into Bridge Mode.  <\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"313\" height=\"160\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/05\/image.png\" alt=\"\" class=\"wp-image-2508\" srcset=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/05\/image.png 313w, https:\/\/increasec.com\/wp-content\/uploads\/2023\/05\/image-300x153.png 300w\" sizes=\"auto, (max-width: 313px) 100vw, 313px\" \/><\/figure>\n\n\n\n<p>tracert shows hop 2 which is the ip address of the upstream ISP router<\/p>\n\n\n\n<p>If the ISP router uses Connection Mode DHCP, switching to Bridged mode is an easy fix.<br>If the Connection Mode is PPPoE, you will need to write down the username and password from your ISP hardware and re-enter that in YOUR firewall.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"256\" height=\"117\" src=\"https:\/\/increasec.com\/wp-content\/uploads\/2023\/05\/image-1.png\" alt=\"\" class=\"wp-image-2509\"\/><\/figure>\n\n\n\n<p>after the ISP hardware is in Bridge Mode there won&#8217;t be any web interface.   The wifi may stop working, if it has any.   To reset the device back to NAT\/Router mode you will need to hold down the hardware reset button for 10 seconds.   It will take a full 5 minutes for it to come back to life.<br><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here are the troubleshooting steps i use 1 sign on to the user PC using TeamViewer\/Splashtop or similar 2 verify client is correct version. v7.0 is available now, Fortinet has&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[75,106],"class_list":["post-1481","post","type-post","status-publish","format-standard","hentry","category-uncategorised","tag-forinet","tag-vpn"],"_links":{"self":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/1481","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1481"}],"version-history":[{"count":4,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/1481\/revisions"}],"predecessor-version":[{"id":2512,"href":"https:\/\/increasec.com\/index.php?rest_route=\/wp\/v2\/posts\/1481\/revisions\/2512"}],"wp:attachment":[{"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1481"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1481"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/increasec.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}