Overview
This article explains common reasons why SSL VPN negotiation may stall at certain percentages and provides possible solutions.
10% - Unable to establish the VPN connection. The VPN server may be unreachable.
Possible Solutions:
- Check whether the PC can access the internet.
- Confirm Remote Gateway matches what was provided by Pacific Solutions.
40% - Unable to establish the VPN connection. The VPN server may be unreachable. (-5)
Possible Solution:
- An encryption mismatch between FortiClient (Windows) Workstation and FortiGate SSL VPN Settings. On the FortiClient (Windows) workstation search bar, go to Internet Explorer (open cmd and type 'iexplore' - it will redirect to Microsoft Edge). Enter Options in the search bar -> Internet options will be grayed out -> Change IE Mode to allow under 'Allow sites to be reloaded in Internet Explorer mode (IE mode)' -> select Advanced (under internet properties). Make sure 'Use TLS 1.2' and 'Use TLS 1.3' are selected. Restart computer and try to connect again.
42 or 43% - sslvpn_login_permission_denied
Possible Solution:
- Check whether you are using the credentials provided by Pacific Solutions are correct.
45% - Unable to establish the VPN connection. The VPN server may be unreachable. (-8)
Possible Solution:
- Check whether you are using the credentials provided by Pacific Solutions are correct.
48% - Credential or SSLVPN configuration is wrong. (-7200)
Possible Solutions:
- Check whether you are using the credentials provided by Pacific Solutions are correct.
- Check if Internet Explorer 'Internet Options' is set to High. If so, please reduce it from 'Medium-High' or 'Medium'
On the FortiClient (Windows) workstation search bar, go to Internet Explorer (open cmd and type 'iexplore' - it will redirect to Microsoft Edge). Enter Options in the search bar -> Internet options will be grayed out -> Change IE Mode to allow under 'Allow sites to be reloaded in Internet Explorer mode (IE mode)' -> select Security -> Reduce to 'Medium-High' or 'Medium.' -> select OK -> Reboot computer and try connecting again.
98% - No error message, it just times out.
Possible Solutions:
-
Completely restart your computer.
Do not just disconnect and reconnect FortiClient. Restarting the computer resets the FortiClient services and your computer's network adapters.
-
Restart your modem/router.
If possible: - Shut down your computer.
- Unplug your modem/router from power for approximately 60 seconds.
- Plug the equipment back in.
- Wait until Internet service is fully restored.
- Start your computer and try FortiClient again.
-
Test from a different Internet connection.
This is the most useful troubleshooting test. If possible, temporarily connect your computer to a mobile phone hotspot and then try FortiClient.- If FortiClient works normally through the hotspot, the issue is most likely related to your normal Internet connection, router, Wi-Fi, or ISP.
-
If the same problem occurs through the hotspot, the issue is more likely related to your computer or FortiClient installation.
-
If you are currently using Wi-Fi, test with Ethernet if possible.
Even a very brief interruption in Wi-Fi connectivity can cause the VPN tunnel to disconnect.
-
Can be caused by network issues
For example, IPv6 to IPv4 connections (not supported), high network latency, blocked traffic, or traffic inspection between FortiClient and FortiGate
- Disable IPv6 under the network adapter: Control Panel -> Network and Internet -> Network and Sharing Center -> Select the Network Adapter -> Properties -> Uncheck Internet Protocol Version 6 (TCP/IPv6). -> Press OK -> Try to connect again.
-
Your FortiClient installation may be corrupted.
- Uninstall the FortiClient Software.
Note: If unable to uninstall through the Windows Control Panel, please run the FortiClient VPN client removal tool as an administrator: https://pacific-solutions.sharefile.com/public/share/web-s3d4d9ec2423246808c022fae591af14d.
- Reboot your PC.
- Uninstall any Microsoft Visual C++ Redistributable package found in the Control Panel
- Reboot PC.
- Install the latest version of Microsoft Visual C++ Redistributable Version: https://aka.ms/vs/17/release/vc_redist.x64.exe
- Reinstall FortiClient: https://pacific-solutions.sharefile.com/public/share/web-s33d69345f216420ab0e8577f6c6ca3c1
- If prompted to reboot your computer, please reboot your computer.
- Try to run the FortiClient VPN client again.