VOE Remote Access

Set up FortiClient VPN in 5 quick steps

Step 1 โ€” Pick your system & download

Click your operating system, then download the installer. Use your work device whenever possible.

๐ŸชŸ

Windows

Windows 10 / 11 (64-bit) ยท 4.9 MB
Download
๐ŸŽ

macOS

FortiClient VPN 7.4.3 ยท 6.6 MB
Download
๐Ÿง

Linux

RHEL / Rocky / Fedora ยท 134 MB
Download

โš ๏ธ The Windows and macOS installers download the full client during setup, so stay connected to the internet while installing.

Step 2 โ€” Install

  1. Run the downloaded FortiClientVPNInstaller.exe. If Windows asks for permission to make changes, click Yes.
  2. Accept the license agreement and click through the installer with the default options.
  3. Wait for the installer to download and install the full client, then restart your computer if prompted.
  1. Open the downloaded .dmg file and double-click the installer inside.
  2. Follow the prompts and enter your Mac password when asked.
  3. If macOS shows a "System Extension Blocked" message, open System Settings โ†’ Privacy & Security and click Allow next to the FortiClient extension, then approve the VPN configuration prompt.
  1. Open a terminal in your Downloads folder and install the package:
    sudo dnf install ./forticlient_vpn_7.4.3.5411_x86_64.rpm
  2. Launch FortiClient from your applications menu (or run forticlient).

Showing instructions for . Wrong system? Windows ยท macOS ยท Linux

Step 3 โ€” Create the VPN connection

  1. Launch FortiClient VPN.
  2. Accept the disclaimer if shown, then click Configure VPN.
  3. At the top of the form, select IPsec VPN (not SSL-VPN).
  4. Fill in the form exactly as follows:
VPNIPsec VPN
Connection NamePSM
Description(leave blank)
Remote Gatewayremote.voe.org
Authentication MethodPre-shared key
Authentication (EAP)Save login
UsernameYour VOE network username
Failover SSL VPN[None]
Single Sign On SettingsLeave unchecked

๐Ÿ”‘ View the pre-shared key here โ€” shown automatically on the VOE network; from home you'll sign in with your VOE network account first.

๐Ÿ“ท Show me what the completed form looks like
FortiClient New VPN Connection screen with IPsec VPN selected, connection name PSM, remote gateway remote.voe.org, and pre-shared key authentication
Use your own username, not the one shown.

Don't click Save yet โ€” the next step fills in the Advanced Settings.

Step 4 โ€” Advanced settings

Still on the same form, expand Advanced Settings โ†’ VPN Settings. The VPN will not connect unless these match exactly.

IKEVersion 2
Address AssignmentMode Config
EncapsulationIKE UDP Port

Phase 1

IKE Proposal โ€” row 1Encryption AES128GCM ยท Authentication PRFSHA384
IKE Proposal โ€” row 2Encryption AES256GCM ยท Authentication PRFSHA384
DH Group20 only (uncheck all others)
Key Life86400 seconds
Local ID(leave blank)
Dead Peer Detectionโœ… Checked
NAT Traversalโœ… Checked
Enable Local LANโฌœ Unchecked

Phase 2

IKE Proposal โ€” row 1Encryption AES128GCM ยท Authentication NONE
IKE Proposal โ€” row 2Encryption AES256GCM ยท Authentication NONE
Key Lifeโœ… Seconds: 43200  ยท  โฌœ KBytes: unchecked
Enable Replay Detectionโœ… Checked
Enable Perfect Forward Secrecy (PFS)โœ… Checked
DH Group20
๐Ÿ“ท Show me what these screens look like
FortiClient Phase 1 settings showing AES128GCM and AES256GCM with PRFSHA384, DH group 20, key life 86400
Phase 1 and the start of Phase 2.
FortiClient Phase 2 settings showing AES-GCM proposals, key life 43200 seconds, replay detection and PFS enabled, DH group 20
Phase 2 โ€” replay detection and PFS enabled, DH Group 20.

When everything matches, click Save.

Step 5 โ€” Connect

  1. On the FortiClient home screen, make sure the PSM connection is selected in the VPN Name dropdown.
  2. Your username should already be filled in. Enter your VOE network password.
  3. Click Connect. The first connection may take 10โ€“20 seconds.
  4. When connected, FortiClient shows the status, duration, and your assigned IP. You can now reach internal VOE resources as if you were in the office.

๐Ÿ’ก To disconnect, open FortiClient and click Disconnect. Always disconnect when you finish working โ€” especially on shared networks.

๐ŸŽ‰ That's it โ€” you're set up. Next time you just open FortiClient, type your password, and connect. If something didn't work, head to the Help step.

Help & troubleshooting

Getting the pre-shared key

View the pre-shared key here โ€” it appears automatically if you're on the VOE network; otherwise sign in with your VOE network username and password. If you can't sign in, email it@voe.org from your VOE email account.

Common issues

"Unable to logon to the server" / wrong credentials

Re-enter your VOE network username and password. The username has no @voe.org suffix.

Stuck at "Connecting" then times out

Re-check every value in Steps 3 and 4 โ€” a single mismatched proposal, DH group, or key-life value will silently fail. Also confirm the pre-shared key was typed correctly.

Connects then drops immediately

Verify Phase 2 settings, especially PFS, DH Group 20, and key life 43200.

Hotel / public Wi-Fi blocks the VPN

Some networks block IPsec (UDP 500/4500). Try a phone hotspot to confirm, then contact IT.

macOS: VPN option missing after install

Allow the FortiClient system extension under System Settings โ†’ Privacy & Security, then reboot.

Still stuck? Email it@voe.org.