IPsec VPN connection enhancements 7.2.1
In 7.2.1, FortiClient connects to IPsec VPN only when it is connected to EMS and EMS is part of a Fortinet Security Fabric with a FortiGate. Otherwise, FortiClient cannot connect to the IPsec VPN tunnel. This enhancement also adds the EMS serial number to FortiOS IPsec VPN logs.
You must also enable vpn-ems-sn-check
in FortiOS global settings by running the following commands:
FGVM02TM123456 # config system global
FGVM02TM123456 (global) # set vpn-ems-sn-check enable
FGVM02TM123456 (global) # end
The following shows the EMS serial number as seen in FortiOS IPsec VPN logs:
FCTVER=7.2.1.XXXX
UID=FDE6A554A2EF4C50BB....
IP=192.168.90.2
MAC=00-15-5d-23-03-2b;00-15-5d-23-03-3f;
HOST=host
USER=ipsec
OSVER=Microsoft Windows 8.0 Professional Edition, 64-bit (build 9200)
REG_STATUS=0
EMSSN=FCTEMS123456...
The following shows the FortiClient GUI when it cannot connect to IPsec VPN due to the conditions not being met.