Technical Tip: Precedence between ZTNA or VPN
| Description | This article describes which connection methodology has greater precedence: FortiClient ZTNA or FortiClient VPN |
| Scope | FortiClient EMS, FortiSASE. |
| Solution | If the same destination is configured within a network and both endpoint profiles are active on a FortiClient: ZTNA Destination and Remote Access, then ZTNA Destination will always take precedence over any VPN, regardless of whether it's SSL, IPSec, IKEv1, or IKEv2.
The only exception would be if, upon connecting to a VPN, the on-fabric detection rule determines that the FortiClient is in the On-Fabric state and the ZTNA Destination profile is disabled in this mode.
![]() |

