{"id":1938,"date":"2016-03-30T00:09:45","date_gmt":"2016-03-30T00:09:45","guid":{"rendered":"http:\/\/pariswells.com\/blog\/?p=1938"},"modified":"2022-03-11T05:47:18","modified_gmt":"2022-03-11T05:47:18","slug":"ssl-vpn-98-no-more-addresses-fortigate","status":"publish","type":"post","link":"https:\/\/pariswells.com\/blog\/random\/ssl-vpn-98-no-more-addresses-fortigate","title":{"rendered":"Forticlient &#8211; SSL VPN 98% &#8220;no more addresses&#8221; fortigate"},"content":{"rendered":"<p>Users who could connect were no longer connecting to our Foritgate<\/p><p>If using VDOM use\u00a0<\/p><p>#conf Global<\/p><p>#diagnose sys top<\/p><p>Check for Free Memory Usage( Should not be over 80% )\u00a0<\/p><p>Enable Debug for VPN<\/p><p>#dia debug en<br \/>#dia debug reset<br \/>#dia debug application sslvpn -1<\/p><p>Then Connect VPN , and check for logs for that user<\/p><p>Found :\u00a0<\/p><p><strong>\u00a0&#8220;no more addresses&#8221; fortigate<\/strong><\/p><p>#diagnose <em>debug disable<\/em><\/p><p>#exec vpn sslvpn list<\/p><p>If using VDOM Use this before<\/p><p>#conf vdom<\/p><p>#edit Vdom Name\u00a0<\/p><p>Users where getting 4 Address in the SSL VPN Sessions instead of one which was filling up the DHCP List<\/p><p>#fnsysctl ps<\/p><p>find the PID of sslvpnd<\/p><p>#run diag sys kill 11\u00a0&lt;pid&gt;<\/p><p>VPN Service will restart Automatically.<\/p><p>&nbsp;<\/p><p id=\"viewer-7jnio\" class=\"XzvDs _208Ie tFDi5 blog-post-text-font blog-post-text-color _2QAo- _25MYV _6RI6N tFDi5 public-DraftStyleDefault-block-depth0 public-DraftStyleDefault-text-ltr\">If FortiClient fails as the following stages, the likely cause is as follows:<\/p><div id=\"viewer-bmg24\" class=\"XzvDs _208Ie tFDi5 blog-post-text-font blog-post-text-color _2QAo- _25MYV _6RI6N tFDi5 public-DraftStyleDefault-block-depth0 public-DraftStyleDefault-text-ltr\">\u00a0<\/div><ul class=\"public-DraftStyleDefault-ul\"><li id=\"viewer-24bp6\" class=\"public-DraftStyleDefault-unorderedListItem\r\n   public-DraftStyleDefault-depth0\r\n   public-DraftStyleDefault-list-ltr public-DraftStyleDefault-reset _2QAo- _25MYV _6RI6N tFDi5\"><p class=\"_208Ie _2QAo- _25MYV _6RI6N tFDi5\">10% \u2013 Local Network\/PC issue<\/p><\/li><li id=\"viewer-c6e58\" class=\"public-DraftStyleDefault-unorderedListItem\r\n   public-DraftStyleDefault-depth0\r\n   public-DraftStyleDefault-list-ltr _2QAo- _25MYV _6RI6N tFDi5\"><p class=\"_208Ie _2QAo- _25MYV _6RI6N tFDi5\">40% \u2013 Application or the Fortigate causing the error, occasionally caused by the local machines\/network setup<\/p><\/li><li id=\"viewer-3mvuc\" class=\"public-DraftStyleDefault-unorderedListItem\r\n   public-DraftStyleDefault-depth0\r\n   public-DraftStyleDefault-list-ltr _2QAo- _25MYV _6RI6N tFDi5\"><p class=\"_208Ie _2QAo- _25MYV _6RI6N tFDi5\">45% \u2013 MultiFactor Authentication<\/p><\/li><li id=\"viewer-el0hg\" class=\"public-DraftStyleDefault-unorderedListItem\r\n   public-DraftStyleDefault-depth0\r\n   public-DraftStyleDefault-list-ltr _2QAo- _25MYV _6RI6N tFDi5\"><p class=\"_208Ie _2QAo- _25MYV _6RI6N tFDi5\">80% \u2013 Username\/Password issue<\/p><\/li><li id=\"viewer-calcc\" class=\"public-DraftStyleDefault-unorderedListItem\r\n   public-DraftStyleDefault-depth0\r\n   public-DraftStyleDefault-list-ltr _2QAo- _25MYV _6RI6N tFDi5\"><p class=\"_208Ie _2QAo- _25MYV _6RI6N tFDi5\">98% \u2013 corruption of services\/often resolved by reinstalling the client on the laptop.<\/p><\/li><\/ul><p>&nbsp;<\/p><p><strong>Client Logging<\/strong><\/p><p>You will want to:<\/p><ol><li>Clear the logs if you have any there.<\/li><li>Set the\u00a0<code>Log Level<\/code>\u00a0to\u00a0<code>Debug<\/code>\u00a0to ensure the highest verbosity. (Make sure to disabled after troubleshooting)<\/li><li>Run the attempt, and then\u00a0<code>Export logs<\/code><\/li><\/ol><p>&nbsp;<\/p><p>&nbsp;<\/p><p class=\"x_MsoNormal\">Client: Access Sydney<\/p><p class=\"x_MsoNormal\">Device: Fortigate 60E<\/p><p class=\"x_MsoNormal\">FortiOS ver 6.4.3<\/p><p class=\"x_MsoNormal\"><b>\u00a0<\/b><\/p><p class=\"x_MsoNormal\"><b>Symptoms:<\/b><\/p><ul type=\"disc\"><li class=\"x_MsoListParagraph\">User connects to VPN but Forticlient errors, Unable to receive SSL VPN tunnel IP address -30<br aria-hidden=\"true\" \/><img loading=\"lazy\" decoding=\"async\" width=\"363\" height=\"155\" class=\"alignnone size-full wp-image-5621  img-responsive\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22ee9214.png\" alt=\"\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22ee9214.png 363w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22ee9214-300x128.png 300w\" sizes=\"auto, (max-width: 363px) 100vw, 363px\" \/>\u00a0<br aria-hidden=\"true\" \/><br aria-hidden=\"true\" \/><\/li><li class=\"x_MsoListParagraph\">Checked the Fortigate, no VPN users connected<\/li><li class=\"x_MsoListParagraph\">20 free IP address in the VPN IP Pool<br aria-hidden=\"true\" \/><br aria-hidden=\"true\" \/><br aria-hidden=\"true\" \/><\/li><\/ul><p class=\"x_MsoNormal\"><b>Troubleshooting:<\/b><\/p><ul type=\"disc\"><li class=\"x_MsoListParagraph\">Enabled debugging, reattempted connection and found error relating to IP allocation failure<\/li><\/ul><p><img loading=\"lazy\" decoding=\"async\" width=\"1096\" height=\"160\" class=\"alignnone size-full wp-image-5622  img-responsive\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22fde7c8.png\" alt=\"\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22fde7c8.png 1096w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22fde7c8-300x44.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22fde7c8-1024x149.png 1024w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22fde7c8-768x112.png 768w\" sizes=\"auto, (max-width: 1096px) 100vw, 1096px\" \/><\/p><p class=\"x_MsoNormal\" aria-hidden=\"true\">\u00a0<\/p><p class=\"x_MsoNormal\" aria-hidden=\"true\">\u00a0<\/p><p class=\"x_MsoNormal\"><b>Quick fix:<\/b>\u00a0killed the sslvpnd process (this will terminate all VPN connections)<\/p><p class=\"x_MsoNormal\" aria-hidden=\"true\">\u00a0<\/p><p class=\"x_MsoNormal\">Found that a later version of FortiOS has fixed this bug:<\/p><p><img loading=\"lazy\" decoding=\"async\" width=\"919\" height=\"66\" class=\"alignnone size-full wp-image-5620  img-responsive\" src=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22e8e0b0.png\" alt=\"\" srcset=\"https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22e8e0b0.png 919w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22e8e0b0-300x22.png 300w, https:\/\/pariswells.com\/blog\/wp-content\/uploads\/2022\/03\/img_622ae22e8e0b0-768x55.png 768w\" sizes=\"auto, (max-width: 919px) 100vw, 919px\" \/><\/p><p class=\"x_MsoNormal\" aria-hidden=\"true\">\u00a0<\/p><p class=\"x_MsoNormal\" aria-hidden=\"true\">\u00a0<\/p>","protected":false},"excerpt":{"rendered":"<p>Users who could connect were no longer connecting to our ForitgateIf using VDOM use\u00a0#conf Global#diagnose sys topCheck for Free Memory Usage( Should not be over 80% )\u00a0Enable [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3780,1392,1391,1199,1393,1251,1250,850,3779,1390],"class_list":["post-1938","post","type-post","status-publish","format-standard","hentry","category-random","tag-3780","tag-5-2-4","tag-debug","tag-dhcp","tag-forticlient","tag-fortigate","tag-fortinet","tag-ssl","tag-unable-to-receive-ssl-vpn-tunnel-ip-address","tag-vdom"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/1938","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/comments?post=1938"}],"version-history":[{"count":5,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/1938\/revisions"}],"predecessor-version":[{"id":5623,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/posts\/1938\/revisions\/5623"}],"wp:attachment":[{"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/media?parent=1938"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/categories?post=1938"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pariswells.com\/blog\/wp-json\/wp\/v2\/tags?post=1938"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}