VPN & Network Steps 1–3 are DIY WFH / on the road

VPN (FortiClient) Won't Connect? 6 Steps to Find the Cause Fast

Working outside the office and FortiClient throws an error or stalls at 98%? This guide shows how to isolate why the VPN won't connect within the first 5 minutes, in the order the Hinet team uses with real clients.

Quick answer

When a VPN won't connect, first ask whether it's one person or many. For one person, check their internet and try a mobile hotspot — if that works, the local network is blocking VPN; if not, check the username/password and licences and reinstall FortiClient. If many people fail at once, check the SSL VPN certificate and policies on the firewall. Plan a move to IPsec VPN: FortiOS 7.6.3 and later no longer support SSL VPN tunnel mode.

Contents
  1. One person or the whole company?
  2. FortiClient error codes
  3. 6 steps to fix the VPN
  4. FortiGate dropping SSL VPN
  5. From Hinet's real cases
  6. When to call an expert
  7. FAQ: VPN won't connect

Is it one person, or the whole company?

This one question rules out half the causes. If only one person can't connect, the problem is usually their internet or their device. If several people fail at once, the problem is the company firewall.

VPN connection failure triage flow If one person is affected, test over a mobile hotspot: if it connects, the local network is blocking VPN; if not, check the account and FortiClient. If many people are affected at once, check the firewall SSL VPN certificate and licences. VPN won't connect One person Many at once Try a mobile hotspot Connects Local network blocks VPN Still fails Check account + FortiClient Check the firewall SSL VPN certificate · Licences User group · Policy
The triage flow the Hinet team uses for VPN issues — always ask “one person or many?” first.

What do FortiClient error codes mean?

The number in brackets at the end of a FortiClient error tells you where to start looking.

Message / codeMeaningCheck first
-14 The VPN server may be unreachableCan't reach the VPN gatewayLocal internet, blocked port, server address / port in the profile
-12 Unable to logon to the serverLogin failedUsername / password, expired password, user group membership
-455 Permission deniedLogin rejectedWrong password, locked account, MFA token failed
-7200 Credential or SSLVPN configuration is wrongCredentials or settings don't match the firewallRealm / port in the profile, user moved to another group
Stuck at 40% / 98%Logged in, but the tunnel couldn't be builtFortiClient virtual adapter, local antivirus / firewall, client version

For causes by the percentage where it stalls, see the Fortinet Community tip.

6 steps to fix a VPN that won't connect

Ordered by how often each cause shows up. Steps 1–2 take under 5 minutes and solve more than half of cases.

  1. Confirm the internet connection works

    Open two or three ordinary websites. If they don't load or are very slow, the problem is the local internet, not the VPN. On hotel or café Wi-Fi, make sure you've signed in to the captive portal.

  2. Test over a mobile hotspot

    This is the fastest way to isolate the cause. Many hotels, cafés and client offices block the ports VPNs use. If it connects over a phone hotspot, the firewall and account are fine — the problem is the network the user is on.

  3. Check username, password and licences

    The password may have expired under company policy, or was changed in Windows but not updated in FortiClient. Also check whether concurrent VPN users have hit the licence limit.

  4. If many people fail at once, check the firewall

    Check whether the SSL VPN certificate has expired — that breaks everyone on the same day. Check user groups and firewall policies, and whether FortiOS was upgraded recently. (Firewall changes should be made by an administrator, with a config backup first.)

  5. Reinstall FortiClient at the company's standard version

    Uninstall, restart, then install the same version the company uses (not necessarily the newest). Then temporarily disable local antivirus / firewall to test whether it blocks the virtual adapter.

  6. VPN connects, but shared drives don't open

    The VPN is working; the problem is routing or DNS. Try \\server-IP\share directly by IP. If that works, it's DNS. If not, ask your administrator to check split tunnelling and the policies to the server.

Tip before travelling: have users test the VPN from home or a hotspot at least once before they leave, and keep IT's number in their phone — if the VPN fails, internal email and files may be out of reach too.

FortiGate is dropping SSL VPN — what should SMEs prepare?

From FortiOS 7.6.3 onwards, Fortinet no longer supports SSL VPN tunnel mode. Organisations that upgrade their firewall need to move remote users to IPsec VPN.

The impact SMEs typically hit is upgrading the firmware and losing VPN for the whole company, because users' FortiClient profiles are still SSL VPN. Plan before upgrading:

  • Confirm whether your FortiGate model and current FortiOS version are affected (Fortinet guidance)
  • Set up IPsec VPN for remote users and pilot it with a small group
  • Prepare new FortiClient profiles and a short user guide before upgrade day
  • Test from several outside networks (home, 4G/5G, hotels) — IPsec can be blocked on networks where SSL VPN used to work
First-hand experience

What the Hinet team has learned from SME VPN cases

30+VPN tickets (FortiClient, WireGuard, GlobalProtect) in 19 months
2first questions on every case: “one person or many?” and “tried a hotspot?”
30minutes — if remote work stalls, we switch to on-site immediately

The most common reports are “I took my laptop outside the office and the VPN stopped working” and “SSL VPN connection is down”. Most are resolved within minutes by the hotspot test, which separates local-network problems from firewall problems.

Another group is VPN connected but shared drives unavailable — not a VPN fault at all, but routing / DNS or folder permissions. Telling these two symptoms apart saves a lot of troubleshooting time.

When should you call an expert?

If several people can't connect at once, firewall settings need changing, or you're about to upgrade FortiOS, let a system administrator handle it.

A wrong firewall change can take the whole office offline. The Hinet team manages Network & Firewall and IT Support Outsourcing for SMEs, both remote and on-site. You can describe the problem to our engineers using the form below.

FAQ: VPN won't connect

Why does the VPN work at home but not at a hotel or café?

Many public networks block the ports or protocols VPNs use. The quickest test is a mobile hotspot: if it connects, the problem is that network, not your account or the company firewall.

How do I fix FortiClient stuck at 98%?

It means login succeeded but the tunnel couldn't be built, often due to a problem with FortiClient's virtual adapter or local antivirus blocking it. Reinstall FortiClient at the company's standard version and temporarily disable antivirus to test.

What does FortiClient error -14 mean?

The computer can't reach the VPN gateway. Check that the internet works, that the server address and port in the profile are correct, and that the network you're on isn't blocking that port.

The whole company lost VPN on the same day — why?

Common causes are an expired SSL VPN certificate on the firewall, a FortiOS upgrade, or a problem with the office's inbound internet. Have an administrator check the firewall immediately.

FortiOS 7.6.3 dropped SSL VPN — what do we need to do?

Before upgrading to FortiOS 7.6.3 or later, move remote users from SSL VPN tunnel mode to IPsec VPN: configure it, pilot with a small group, and give users new FortiClient profiles before upgrade day.

The VPN connects but the shared drive won't open. What now?

Try reaching the server by IP, e.g. \\192.168.1.10\share. If that works, it's a DNS issue; if not, ask your administrator to check routing, split tunnelling and the policies that let VPN users reach the server.

References

Technically reviewed by the Hinet Computer System engineering team · Last updated 10 Oct 2026

Hinet IT Support

Still stuck? Let the Hinet team fix it

Describe the problem briefly. Our engineers will check both the firewall and the user's device, and get back to you within 1 business day.

  • Supporting Thai businesses since 2004
  • FortiGate / FortiClient, WireGuard and other VPN platforms
  • Free initial assessment, no obligation

Report an IT issue

Fields marked * are required

We only use your details to follow up on this issue, per our privacy policy.

LINE Get help