Troubleshooting Tip: Windows 10/11 unable to connect to the SSL VPN using TLS 1.3 via FortiClient (2024)

FortiGate SSL VPN supports TLS 1.3. To connect to FortiGate SSL VPN using TLS 1.3, it is necessary to enable TLS 1.3 in Windows 10/11. Normally it is possible to enable it via the Internet browser properties:

  • In Windows computer, start the Run prompt (Win + R) and type 'inetcpl.cpl', then press the Enter key.
  • The Internet Properties window will be opened. Go to the Advanced section.
  • Under the security section, check the box TLS 1.3.
  • Apply the changes and restart the browser.

Troubleshooting Tip: Windows 10/11 unable to connect to the SSL VPN using TLS 1.3 via FortiClient (1)

If the FortiClient still fails to connect to FortiGate SSL VPN using TLS 1.3 (Webmode is working fine), then it is necessary to check and edit the computer registry.

Troubleshooting Tip: Windows 10/11 unable to connect to the SSL VPN using TLS 1.3 via FortiClient (2)

First, collectthe FortiGate SSL VPN debug. From the debug it is possible to see that FortiClient is not able to initiate an SSL connection using TLS 1.3:

dia de dis

dia de reset

dia de app sslvpn -1

dia de enable

FortiGate SSL VPN Debug Output:

// Forticlient failed to connect //
[19293:root:2fc]allocSSLConn:307 sconn 0x7f0946f57a00 (0:root)
[19293:root:2fc]SSL state:before SSL initialization (10.47.4.151)
[19293:root:2fc]SSL state:before SSL initialization:DH lib(10.47.4.151)
[19293:root:2fc]SSL_accept failed, 5:(null)
[19293:root:2fc]Destroy sconn 0x7f0946f57a00, connSize=0. (root)

// Webmode can access using TLS 1.3 //
[19293:root:302]SSL established: TLSv1.3 TLS_AES_256_GCM_SHA384 <<===
[19293:root:302]No client certificate
[19293:root:302]req: /remote/login
[19293:root:302]rmt_web_auth_info_parser_common:492 no session id in auth info
[19293:root:302]rmt_web_get_access_cache:841 invalid cache, ret=4103
[19293:root:302]User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36 Edg/116.0.1938.81 <<====

Next, check and edit the computer registry to enable TLS 1.3:

  • Go to \HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols
  • If 'TLS 1.3' is not displaying as a child path under 'Protocols', create it. 'Right-click' 'Protocols', create 'new key', and name it 'TLS 1.3'.

    Troubleshooting Tip: Windows 10/11 unable to connect to the SSL VPN using TLS 1.3 via FortiClient (3)

  • Then create another new key under 'TLS 1.3', and name it 'Client'.
  • In the 'Client' section,create 2 DWORD (32-bit) values, name them 'DisabledByDefault' and 'Enabled' with default value 0.

    Troubleshooting Tip: Windows 10/11 unable to connect to the SSL VPN using TLS 1.3 via FortiClient (4)

  • For 'Enabled', change the value to '1'.

    Troubleshooting Tip: Windows 10/11 unable to connect to the SSL VPN using TLS 1.3 via FortiClient (5)

  • Final Look at the registry:

    Troubleshooting Tip: Windows 10/11 unable to connect to the SSL VPN using TLS 1.3 via FortiClient (6)

  • Apply the changes and close the registry editor window.
  • Restart the computer.

After restarting the computer, the FortiClient can connect to the FortiGate SSL VPN using TLS 1.3. SSL VPN debug on FortiGate:

[19293:root:31d]SSL established: TLSv1.3 TLS_AES_256_GCM_SHA384<-
[19293:root:31d]req: /remote/login
[19293:root:31d]User Agent: FortiSSLVPN (Windows NT; SV1 [SV{v=02.01; f=07;}])<-

[19293:root:31d]sslvpn_authenticate_user:183 authenticate user: [local] <-
[19293:root:31d][fam_auth_send_req_internal:652] The user local is authenticated.
[19293:root:31d]fam_do_cb:665 fnbamd return auth success.

Troubleshooting Tip: Windows 10/11 unable to connect to the SSL VPN using TLS 1.3 via FortiClient (7)

Troubleshooting Tip: Windows 10/11 unable to connect to the SSL VPN using TLS 1.3 via FortiClient (2024)
Top Articles
Stock trader salary ‐ CareerExplorer
2024 Garbage Pail Kids Series 1 Checklist Spotlight
Lowe's Garden Fence Roll
Www.politicser.com Pepperboy News
Kobold Beast Tribe Guide and Rewards
Google Jobs Denver
Hawkeye 2021 123Movies
41 annonces BMW Z3 occasion - ParuVendu.fr
Sams Gas Price Fairview Heights Il
Herbalism Guide Tbc
Citymd West 146Th Urgent Care - Nyc Photos
Where does insurance expense go in accounting?
Craigslist Blackshear Ga
111 Cubic Inch To Cc
Everything We Know About Gladiator 2
Wausau Obits Legacy
Trivago Sf
Where Is The Nearest Popeyes
Drago Funeral Home & Cremation Services Obituaries
Bible Gateway passage: Revelation 3 - New Living Translation
Katie Sigmond Hot Pics
Greyson Alexander Thorn
Gina Wilson Angle Addition Postulate
Olivia Maeday
Truck from Finland, used truck for sale from Finland
Umn Biology
Maisons près d'une ville - Štanga - Location de vacances à proximité d'une ville - Štanga | Résultats 201
Login.castlebranch.com
Fedex Walgreens Pickup Times
Goodwill Houston Select Stores Photos
آدرس جدید بند موویز
Royals op zondag - "Een advertentie voor Center Parcs" of wat moeten we denken van de laatste video van prinses Kate?
The Land Book 9 Release Date 2023
Marie Peppers Chronic Care Management
Scottsboro Daily Sentinel Obituaries
Emerge Ortho Kronos
Property Skipper Bermuda
Best Restaurant In Glendale Az
Insideaveritt/Myportal
Adam Bartley Net Worth
What to Do at The 2024 Charlotte International Arts Festival | Queen City Nerve
Juiced Banned Ad
Senior Houses For Sale Near Me
844 386 9815
Truck Works Dothan Alabama
Timothy Warren Cobb Obituary
Unblocked Games - Gun Mayhem
Boyfriends Extra Chapter 6
Premiumbukkake Tour
Verizon Forum Gac Family
Bunbrat
Latest Posts
Article information

Author: Nicola Considine CPA

Last Updated:

Views: 5829

Rating: 4.9 / 5 (69 voted)

Reviews: 92% of readers found this page helpful

Author information

Name: Nicola Considine CPA

Birthday: 1993-02-26

Address: 3809 Clinton Inlet, East Aleisha, UT 46318-2392

Phone: +2681424145499

Job: Government Technician

Hobby: Calligraphy, Lego building, Worldbuilding, Shooting, Bird watching, Shopping, Cooking

Introduction: My name is Nicola Considine CPA, I am a determined, witty, powerful, brainy, open, smiling, proud person who loves writing and wants to share my knowledge and understanding with you.