This section provides an example of a non-default IPsec VPN configuration. You can use this configuration if both of the following symptoms occur:
- FortiClient fails to connect to IPsec VPN
- When you view the FortiGate IKE debug log, you see that FortiOS sends
R_U_THEREto FortiClient, but there is no reply, and it times out.
In this case, you can increase the FortiGate DPD wait time and/or enable FortiClient IPsec multithread mode. However, it is recommended not to enable FortiClient IPsec multithread mode if it is not necessary. You must make changes to the FortiGate and FortiClient configurations.
To configure the FortiGate:
config vpn ipsec phase1-interface
edit <your IPsec VPN>
set dpd-retrycount <configure a higher number>
set dpd-retryinterval <configure a higher number>
To configure FortiClient:
Enable multithread mode on FortiClient using the following XML configuration:
<name>your IPsec VPN</name>