Fortinet white logo
Fortinet white logo

New Features

IPsec VPN connection enhancements 7.2.1

IPsec VPN connection enhancements 7.2.1

In 7.2.1, FortiClient connects to IPsec VPN only when it is connected to EMS and EMS is part of a Fortinet Security Fabric with a FortiGate. Otherwise, FortiClient cannot connect to the IPsec VPN tunnel. This enhancement also adds the EMS serial number to FortiOS IPsec VPN logs.

You must also enable vpn-ems-sn-check in FortiOS global settings by running the following commands:

FGVM02TM123456 # config system global

FGVM02TM123456 (global) # set vpn-ems-sn-check enable

FGVM02TM123456 (global) # end

The following shows the EMS serial number as seen in FortiOS IPsec VPN logs:

FCTVER=7.2.1.XXXX

UID=FDE6A554A2EF4C50BB....

IP=192.168.90.2

MAC=00-15-5d-23-03-2b;00-15-5d-23-03-3f;

HOST=host

USER=ipsec

OSVER=Microsoft Windows 8.0 Professional Edition, 64-bit (build 9200)

REG_STATUS=0

EMSSN=FCTEMS123456...

The following shows the FortiClient GUI when it cannot connect to IPsec VPN due to the conditions not being met.

IPsec VPN connection enhancements 7.2.1

IPsec VPN connection enhancements 7.2.1

In 7.2.1, FortiClient connects to IPsec VPN only when it is connected to EMS and EMS is part of a Fortinet Security Fabric with a FortiGate. Otherwise, FortiClient cannot connect to the IPsec VPN tunnel. This enhancement also adds the EMS serial number to FortiOS IPsec VPN logs.

You must also enable vpn-ems-sn-check in FortiOS global settings by running the following commands:

FGVM02TM123456 # config system global

FGVM02TM123456 (global) # set vpn-ems-sn-check enable

FGVM02TM123456 (global) # end

The following shows the EMS serial number as seen in FortiOS IPsec VPN logs:

FCTVER=7.2.1.XXXX

UID=FDE6A554A2EF4C50BB....

IP=192.168.90.2

MAC=00-15-5d-23-03-2b;00-15-5d-23-03-3f;

HOST=host

USER=ipsec

OSVER=Microsoft Windows 8.0 Professional Edition, 64-bit (build 9200)

REG_STATUS=0

EMSSN=FCTEMS123456...

The following shows the FortiClient GUI when it cannot connect to IPsec VPN due to the conditions not being met.