Quick answer
When a VPN won't connect, first ask whether it's one person or many. For one person, check their internet and try a mobile hotspot — if that works, the local network is blocking VPN; if not, check the username/password and licences and reinstall FortiClient. If many people fail at once, check the SSL VPN certificate and policies on the firewall. Plan a move to IPsec VPN: FortiOS 7.6.3 and later no longer support SSL VPN tunnel mode.
Contents
Is it one person, or the whole company?
This one question rules out half the causes. If only one person can't connect, the problem is usually their internet or their device. If several people fail at once, the problem is the company firewall.
What do FortiClient error codes mean?
The number in brackets at the end of a FortiClient error tells you where to start looking.
| Message / code | Meaning | Check first |
|---|---|---|
-14 The VPN server may be unreachable | Can't reach the VPN gateway | Local internet, blocked port, server address / port in the profile |
-12 Unable to logon to the server | Login failed | Username / password, expired password, user group membership |
-455 Permission denied | Login rejected | Wrong password, locked account, MFA token failed |
-7200 Credential or SSLVPN configuration is wrong | Credentials or settings don't match the firewall | Realm / port in the profile, user moved to another group |
| Stuck at 40% / 98% | Logged in, but the tunnel couldn't be built | FortiClient virtual adapter, local antivirus / firewall, client version |
For causes by the percentage where it stalls, see the Fortinet Community tip.
6 steps to fix a VPN that won't connect
Ordered by how often each cause shows up. Steps 1–2 take under 5 minutes and solve more than half of cases.
-
Confirm the internet connection works
Open two or three ordinary websites. If they don't load or are very slow, the problem is the local internet, not the VPN. On hotel or café Wi-Fi, make sure you've signed in to the captive portal.
-
Test over a mobile hotspot
This is the fastest way to isolate the cause. Many hotels, cafés and client offices block the ports VPNs use. If it connects over a phone hotspot, the firewall and account are fine — the problem is the network the user is on.
-
Check username, password and licences
The password may have expired under company policy, or was changed in Windows but not updated in FortiClient. Also check whether concurrent VPN users have hit the licence limit.
-
If many people fail at once, check the firewall
Check whether the SSL VPN certificate has expired — that breaks everyone on the same day. Check user groups and firewall policies, and whether FortiOS was upgraded recently. (Firewall changes should be made by an administrator, with a config backup first.)
-
Reinstall FortiClient at the company's standard version
Uninstall, restart, then install the same version the company uses (not necessarily the newest). Then temporarily disable local antivirus / firewall to test whether it blocks the virtual adapter.
-
VPN connects, but shared drives don't open
The VPN is working; the problem is routing or DNS. Try
\\server-IP\sharedirectly by IP. If that works, it's DNS. If not, ask your administrator to check split tunnelling and the policies to the server.
FortiGate is dropping SSL VPN — what should SMEs prepare?
From FortiOS 7.6.3 onwards, Fortinet no longer supports SSL VPN tunnel mode. Organisations that upgrade their firewall need to move remote users to IPsec VPN.
The impact SMEs typically hit is upgrading the firmware and losing VPN for the whole company, because users' FortiClient profiles are still SSL VPN. Plan before upgrading:
- Confirm whether your FortiGate model and current FortiOS version are affected (Fortinet guidance)
- Set up IPsec VPN for remote users and pilot it with a small group
- Prepare new FortiClient profiles and a short user guide before upgrade day
- Test from several outside networks (home, 4G/5G, hotels) — IPsec can be blocked on networks where SSL VPN used to work
What the Hinet team has learned from SME VPN cases
The most common reports are “I took my laptop outside the office and the VPN stopped working” and “SSL VPN connection is down”. Most are resolved within minutes by the hotspot test, which separates local-network problems from firewall problems.
Another group is VPN connected but shared drives unavailable — not a VPN fault at all, but routing / DNS or folder permissions. Telling these two symptoms apart saves a lot of troubleshooting time.
When should you call an expert?
If several people can't connect at once, firewall settings need changing, or you're about to upgrade FortiOS, let a system administrator handle it.
A wrong firewall change can take the whole office offline. The Hinet team manages Network & Firewall and IT Support Outsourcing for SMEs, both remote and on-site. You can describe the problem to our engineers using the form below.
FAQ: VPN won't connect
Why does the VPN work at home but not at a hotel or café?
Many public networks block the ports or protocols VPNs use. The quickest test is a mobile hotspot: if it connects, the problem is that network, not your account or the company firewall.
How do I fix FortiClient stuck at 98%?
It means login succeeded but the tunnel couldn't be built, often due to a problem with FortiClient's virtual adapter or local antivirus blocking it. Reinstall FortiClient at the company's standard version and temporarily disable antivirus to test.
What does FortiClient error -14 mean?
The computer can't reach the VPN gateway. Check that the internet works, that the server address and port in the profile are correct, and that the network you're on isn't blocking that port.
The whole company lost VPN on the same day — why?
Common causes are an expired SSL VPN certificate on the firewall, a FortiOS upgrade, or a problem with the office's inbound internet. Have an administrator check the firewall immediately.
FortiOS 7.6.3 dropped SSL VPN — what do we need to do?
Before upgrading to FortiOS 7.6.3 or later, move remote users from SSL VPN tunnel mode to IPsec VPN: configure it, pilot with a small group, and give users new FortiClient profiles before upgrade day.
The VPN connects but the shared drive won't open. What now?
Try reaching the server by IP, e.g. \\192.168.1.10\share. If that works, it's a DNS issue; if not, ask your administrator to check routing, split tunnelling and the policies that let VPN users reach the server.
References
- Fortinet Community — Error: The VPN server may be unreachable (-14)
- Fortinet Community — SSL VPN failure at specific percentages
- Fortinet Community — SSL VPN support on FortiGate models
- Fortinet Community — Migrate from SSL VPN web mode
Related guides
Technically reviewed by the Hinet Computer System engineering team · Last updated 10 Oct 2026