Skip to main content
achu
Staff
Staff
January 6, 2026

Technical Tip: Unable to create SSL VPN firewall policy with VIP as the destination

  • January 6, 2026
  • 0 replies
  • 254 views
Description

This article describes the issue in creating an SSL VPN firewall policy in FortiOS version 7.0.17, where the destination is a Virtual IP. An error message is shown below.

 

Image0.png

 

At v7.2.x like v7.2.6, the exact error shows up when attempting to create a firewall policy, as shown below.

 

Error.png

Scope FortiOS.
Solution

Solution:

Upgrade FortiGate to FortiOS version 7.2.8 or above. 

 

Workaround:

Disable web mode in the SSL VPN portal. To disable web mode, go to VPN -> SSL-VPN Portals -> Edit portal -> Disable web mode -> Select Ok.

 

Image1.png