Forticlient hanging at "connecting" when trying to establish connection

I have 2 users who are unable to connect to a tenant VPN. One of them is in Pakistan, one is in the Philippines. The Firewall they are trying to connect to is in Canada. When attempting to connect either of them to the VPN using the Forticlient VPN software it looks to just hang at “connecting”. No progress bar, no percent showing connection status. The app itself isn’t frozen, I can still interact with it. There are no error messages, no warnings or timeouts, and it never progresses. One of the users left it “connecting” overnight and it was still like that in the morning.

I have tested both user’s credentials myself using my own Forticlient and it works perfectly (I am in the same city as the tenant firewall).

I have tested both user internet connections and they seem stable. Not lightning fast but around 30-50mbps up and 5-10 down. Enough that I can connect to their computers with a remote session using third-party software and remain stable and connected.

Is there anything else I can check to figure out where this problem is coming from? Has anyone encountered this specific constant “connecting” issue before with no timeouts or errors? As a note I have connected other users from these countries through this specific VPN in the past with no problems. I have just started encountering this as of about a month and a half ago.

Edit: Both users are on Windows 10 though I don’t have the specific hardware configurations handy.

Edit 2: Users can ping the firewall IP.

Wow, finally a post with something I directly experienced!

I encountered this last week with my own VPN connection and the fix was entirely uninteresting. I uninstalled and reinstalled the FortiVPN client and it started working perfectly.

The only difference is that I was testing MFA prompts, but probably wasn’t specific to that

SSL VPN or IPSEC VPN?

Can you see their connection attempts in the firewall when doing a packet capture?

Are you allowing vpn connections from their IP?

do you hvae the error 6005 in the notifications by any chance ? If yes, go to the users certificates and look for (mostly adobe) CA certificates there and move them to like hte trusted Persons folder

Update here for anyone who may happen upon this post. I solved the issue by downloading an earlier version of Forticlient. I wasn’t looking for any particular version but I ended up using version 6.2.6. Works perfectly. Still have no idea why, or what was causing the issue, but the older version worked.

SSL VPN.

I’m having trouble getting a hold of the users right now to try and run a packet capture on their connection attempt, but both their computers can ping the firewall IP.

Will update when I can get packet details.

I double checked our settings to ensure no rules or filters got added that I did not know about. I currently don’t have anything in place which would block connections from the user’s IP addresses or IP addresses from their region.