VOE Remote Access

Set up FortiClient VPN in 5 quick steps

Step 1 โ€” Pick your system & download

Click your operating system, then download the installer. Use your work device whenever possible.

๐ŸชŸ

Windows

VPN-Only client ยท Windows 10 / 11
Always the latest version
Download
๐ŸŽ

macOS

VPN-Only client
Always the latest version
Download
๐Ÿง

Linux

RHEL / Rocky / Fedora (RPM)
Always the latest version
Download
๐Ÿค–

Android

FortiClient VPN on Google Play
Google Play
๐Ÿ“ฑ

iPhone / iPad

FortiClient VPN on the App Store
App Store

โš ๏ธ The Windows and macOS installers download the full client during setup, so stay connected to the internet while installing.

Step 2 โ€” Install

  1. Run the downloaded FortiClientVPNInstaller.exe. If Windows asks for permission to make changes, click Yes.
  2. Accept the license agreement and click through the installer with the default options.
  3. Wait for the installer to download and install the full client, then restart your computer if prompted.
  1. Open the downloaded .dmg file and double-click the installer inside.
  2. Follow the prompts and enter your Mac password when asked.
  3. If macOS shows a "System Extension Blocked" message, open System Settings โ†’ Privacy & Security and click Allow next to the FortiClient extension, then approve the VPN configuration prompt.
  1. Open a terminal and install the downloaded package:
    sudo dnf install ~/Downloads/forticlient_vpn_*_x86_64.rpm
  2. Launch FortiClient from your applications menu (or run forticlient).
  1. Install FortiClient VPN by Fortinet from Google Play.
  2. Open the app and accept the permissions it requests โ€” including the prompt to allow it to create VPN connections.
  1. Install FortiClient VPN by Fortinet from the App Store.
  2. Open the app and tap Allow when iOS asks to add VPN configurations (you may need to confirm with Face ID or your passcode).

Showing instructions for . Wrong system? Windows ยท macOS ยท Linux ยท Android ยท iPhone/iPad

Step 3 โ€” Create the VPN connection

  1. Launch FortiClient VPN.
  2. Accept the disclaimer if shown, then click Configure VPN.
  3. At the top of the form, select IPsec VPN (not SSL-VPN).
  4. Fill in the form exactly as follows:
VPNIPsec VPN
Connection NamePSM
DescriptionPerry Stone Ministries (optional)
Remote Gatewayremote.voe.org
Authentication MethodPre-shared key
Authentication (XAuth)Save login
UsernameYour domain network username โ€” the one you log in to your work computer with, not your email address
Enable Single Sign On (SSO)Leave unchecked

๐Ÿ“ฑ On Android and iPhone/iPad, the FortiClient VPN app asks for these same values when you add an IPsec VPN connection โ€” field names may differ slightly.

๐Ÿ”‘ View the pre-shared key here โ€” shown automatically on the VOE network; from home you'll sign in with your VOE network account first.

๐Ÿ“ท Show me what the completed form looks like
FortiClient VPN-Only New VPN Connection screen with IPsec VPN selected, connection name PSM, remote gateway remote.voe.org, and pre-shared key authentication
Type your own domain username in the Username field.

Don't click Save yet โ€” the next step fills in the Advanced Settings.

Step 4 โ€” Advanced settings

Still on the same form, expand Advanced Settings โ†’ VPN Settings. The VPN will not connect unless these match exactly.

IKEVersion 2
Address AssignmentMode Config

Phase 1

IKE Proposal โ€” row 1Encryption AES256GCM ยท Authentication PRFSHA384
IKE Proposal โ€” row 2Encryption AES256GCM ยท Authentication PRFSHA384
DH Group20 only (uncheck all others)
Key Life86400 seconds
Local ID(leave blank)
Dead Peer Detectionโœ… Checked
NAT Traversalโœ… Checked (if shown)

Phase 2

IKE Proposal โ€” row 1Encryption AES128GCM ยท Authentication NONE
IKE Proposal โ€” row 2Encryption AES256GCM ยท Authentication NONE
Key Lifeโœ… Seconds: 43200  ยท  โฌœ KBytes: unchecked
Enable Replay Detectionโœ… Checked
Enable Perfect Forward Secrecy (PFS)โœ… Checked
DH Group20
๐Ÿ“ท Show me what this screen looks like
FortiClient VPN-Only advanced settings showing IKE version 2, mode config, Phase 1 AES256GCM with PRFSHA384 and DH group 20, Phase 2 AES-GCM proposals with key life 43200 seconds
Advanced Settings โ€” IKE, Phase 1, and Phase 2.

When everything matches, click Save.

Step 5 โ€” Connect

  1. On the FortiClient home screen, make sure the PSM connection is selected in the VPN Name dropdown.
  2. Your username should already be filled in. Enter your VOE network password.
  3. Click Connect. The first connection may take 10โ€“20 seconds.
  4. When connected, FortiClient shows the status, duration, and your assigned IP. You can now reach internal VOE resources as if you were in the office.

๐Ÿ’ก To disconnect, open FortiClient and click Disconnect. Always disconnect when you finish working โ€” especially on shared networks.

๐ŸŽ‰ That's it โ€” you're set up. Next time you just open FortiClient, type your password, and connect. If something didn't work, head to the Help step.

Help & troubleshooting

Getting the pre-shared key

View the pre-shared key here โ€” it appears automatically if you're on the VOE network; otherwise sign in with your VOE network username and password. If you can't sign in, email it@voe.org from your VOE email account.

Common issues

"Unable to logon to the server" / wrong credentials

Re-enter your VOE network username and password. The username has no @voe.org suffix.

Stuck at "Connecting" then times out

Re-check every value in Steps 3 and 4 โ€” a single mismatched proposal, DH group, or key-life value will silently fail. Also confirm the pre-shared key was typed correctly.

Connects then drops immediately

Verify Phase 2 settings, especially PFS, DH Group 20, and key life 43200.

Hotel / public Wi-Fi blocks the VPN

Some networks block IPsec (UDP 500/4500). Try a phone hotspot to confirm, then contact IT.

macOS: VPN option missing after install

Allow the FortiClient system extension under System Settings โ†’ Privacy & Security, then reboot.

Still stuck? Email it@voe.org.