<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VPN Archives - CarlStanley.com</title>
	<atom:link href="https://carlstanley.com/category/network/vpn/feed/" rel="self" type="application/rss+xml" />
	<link>https://carlstanley.com/category/network/vpn/</link>
	<description>A resource for Network and Systems Admins</description>
	<lastBuildDate>Fri, 28 May 2021 12:34:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>
	<item>
		<title>How to fix: FortiClient Connection Error  -112</title>
		<link>https://carlstanley.com/how-to-fix-forticlient-connection-error-112/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-to-fix-forticlient-connection-error-112</link>
					<comments>https://carlstanley.com/how-to-fix-forticlient-connection-error-112/#respond</comments>
		
		<dc:creator><![CDATA[Carl]]></dc:creator>
		<pubDate>Thu, 27 May 2021 18:16:26 +0000</pubDate>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[FortiClient]]></category>
		<category><![CDATA[FortiGate]]></category>
		<guid isPermaLink="false">https://carlstanley.com/?p=259</guid>

					<description><![CDATA[<p>Problem: Some users trying to connect to VPN using FortiClient receive the error &#8220;Connection Error!&#8221; This error appears with no apparent pattern in OS or FortiClient version. This error on its own is not helpful. For more detail export the<span class="ellipsis">&#8230;</span></p>
<div class="read-more"><a href="https://carlstanley.com/how-to-fix-forticlient-connection-error-112/">Read more <span class="screen-reader-text">How to fix: FortiClient Connection Error  -112</span><span class="meta-nav"> &#8250;</span></a></div>
<p><!-- end of .read-more --></p>
<p>The post <a href="https://carlstanley.com/how-to-fix-forticlient-connection-error-112/">How to fix: FortiClient Connection Error  -112</a> appeared first on <a href="https://carlstanley.com">CarlStanley.com</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><a href="https://carlstanley.com/wp-content/uploads/2021/05/image-1.png"><img fetchpriority="high" decoding="async" src="https://carlstanley.com/wp-content/uploads/2021/05/image-1.png" alt="" class="wp-image-262" width="370" height="249" srcset="https://carlstanley.com/wp-content/uploads/2021/05/image-1.png 740w, https://carlstanley.com/wp-content/uploads/2021/05/image-1-300x202.png 300w, https://carlstanley.com/wp-content/uploads/2021/05/image-1-100x67.png 100w, https://carlstanley.com/wp-content/uploads/2021/05/image-1-150x101.png 150w, https://carlstanley.com/wp-content/uploads/2021/05/image-1-200x135.png 200w, https://carlstanley.com/wp-content/uploads/2021/05/image-1-450x303.png 450w, https://carlstanley.com/wp-content/uploads/2021/05/image-1-600x404.png 600w" sizes="(max-width: 370px) 100vw, 370px" /></a><figcaption>This error is from Big Sur, but a similar message appears on Windows and other MacOS versions.</figcaption></figure></div>



<p><strong><em>Problem:</em></strong> Some users trying to connect to VPN using FortiClient receive the error &#8220;Connection Error!&#8221; This error appears with no apparent pattern in OS or FortiClient version.</p>



<span id="more-259"></span>



<p>This error on its own is not helpful. For more detail export the FortiClient logs and open fortiagent.log:</p>



<p><code>20210524 13:07:34.070 [sslvpn:INFO] unknown:0 try to get cookie for the first time<br>20210524 13:07:35.084 [sslvpn:EROR] unknown:0 no SVPNCOOKIE found<br>20210524 13:07:35.085 [sslvpn:EROR] libsslvpn:587 Failed to login to fortigate : -112<br>20210524 13:07:35.085 [fctgui:EROR] FCTVpnConnection:1704 -112 -<br>20210524 13:07:35.085 [fctgui:INFO] FCTVpnConnection:1760 failure happens so terminate this vpn connection</code></p>



<p>&#8220;Failed to login to fortigate : -112&#8221; was a consistent error on the non-working clients.  I also noted codes -111 and -113 on a couple machines.  Most of my research into this error indicates that it can be resolved by trying different versions of the client.  Try it, it may work for you.  But for me I tried several different versions with no luck. I had to keep digging.</p>



<p>In my case this error is caused by how we used AD to provision VPN. We use nested security groups and gave the parent group VPN access. Normally this is a good practice as it makes management easy but the FortiGate didn&#8217;t like it. The result was that some users worked just fine while others didn&#8217;t. The ones who did work were direct members of the group.</p>



<p><em><strong>How to fix:</strong> </em>You could change your AD group membership and add people directly, but if you have a lot of users that&#8217;s not ideal.  Instead, modify the VPN User Group on the FortiGate so that the nested AD groups are specified directly in the Remote Groups section. You can specify multiple groups.</p>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><a href="https://carlstanley.com/wp-content/uploads/2021/05/image-2.png"><img decoding="async" src="https://carlstanley.com/wp-content/uploads/2021/05/image-2-1024x650.png" alt="" class="wp-image-263" width="768" height="488" srcset="https://carlstanley.com/wp-content/uploads/2021/05/image-2-1024x650.png 1024w, https://carlstanley.com/wp-content/uploads/2021/05/image-2-300x190.png 300w, https://carlstanley.com/wp-content/uploads/2021/05/image-2-768x487.png 768w, https://carlstanley.com/wp-content/uploads/2021/05/image-2-1536x975.png 1536w, https://carlstanley.com/wp-content/uploads/2021/05/image-2-100x63.png 100w, https://carlstanley.com/wp-content/uploads/2021/05/image-2-150x95.png 150w, https://carlstanley.com/wp-content/uploads/2021/05/image-2-200x127.png 200w, https://carlstanley.com/wp-content/uploads/2021/05/image-2-450x286.png 450w, https://carlstanley.com/wp-content/uploads/2021/05/image-2-600x381.png 600w, https://carlstanley.com/wp-content/uploads/2021/05/image-2-900x571.png 900w, https://carlstanley.com/wp-content/uploads/2021/05/image-2.png 1730w" sizes="(max-width: 768px) 100vw, 768px" /></a><figcaption>Add your nested groups directly to the Remote Groups</figcaption></figure></div>
<p>The post <a href="https://carlstanley.com/how-to-fix-forticlient-connection-error-112/">How to fix: FortiClient Connection Error  -112</a> appeared first on <a href="https://carlstanley.com">CarlStanley.com</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://carlstanley.com/how-to-fix-forticlient-connection-error-112/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
