• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 4439
  • Last Modified:

Cisco VPN client to Fortigate 110c


We have a Cisco Client etsablishing an IPSEC vpn to a Fortigate 110C. Works like a charm for all users except one, this user is using 3 G mobile broadband as is getting disconnected every five minutes. All othe users a up most of the working day.

  • 2
1 Solution
"Works like a charm for all users except one, this user is using 3 G mobile broadband as is getting disconnected every five minutes"
So, you think that this one user is getting connected to the VPN successfully, at least occasionally?
If so, then the issue is not a VPN encryption issue, but an Internet provider reliability issue, I think.
Here is a link regarding iPhone on AT&T o er 3G, and VPN issues due to network congestion.
dlg654Author Commented:
User is getting connected and then every five to 10 minutes gets disconnected. Dont think the problem is congestion as a few weeks ago when they were connecting to a Cisco box they did not get dropout. Don't think it is the Fortigate as the non wireless connected users are getting less dropouts then when they were connecting to the Cisco.

Hi dlg654,

We had a similar issue with a mobile network provider in the UK, it turned out to be a limitation of the particular APN they provided.

They provided an alternative one that was only for VPN users which gave users a public IP and did not go through their DPI process.

Does your 3G operator provide a similar setup?

The only other thing I can think is to enable autokey keep alive on the firewall and set the keylife to sub 10 minutes so the tunnel can rekey before it drops.

dlg654Author Commented:
Problem turned out to be MTU of the Fortigate firewall. Changing the MTU settings on the firewall from 1400 to 1450 elliminated the problem.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

We Need Your Input!

WatchGuard is currently running a beta program for our new macOS Host Sensor for our Threat Detection and Response service. We're looking for more macOS users to help provide insight and feedback to help us make the product even better. Please sign up for our beta program today!

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now