Skip to main content
vifi
Staff
Staff
April 11, 2025

Troubleshooting Tip: SSL VPN connection fails when ssl.root interface is added to a zone

  • April 11, 2025
  • 0 replies
  • 942 views
Description This article describes an issue where users are unable to connect to SSL VPN when the ssl.root interface is assigned to a zone.
Scope FortiGate v7.4.6, v7.4.7, v7.6.2.
Solution

When ssl.root interface is added to a zone, SSL VPN connections fail.

 

config system zone
    edit "VPN"
        set interface "VPN1" "ssl.root"
    next

SSL VPN debug logs may not display any output at the time of the issue. Additionally, the SSL VPN daemon (sslvpnd) process may be failing to start.


diagnose debug app sslvpnd -1 <----- Debugs do not print any output.
diagnose debug enable
diagnose sys process pidof sslvpnd <----- Process ID of sslvpnd daemon is not listed.

This issue has been resolved in v7.6.3.


Note:

Starting from v7.6.3, SSL VPN tunnel mode is no longer supported. This applies to all FortiGate models.


Workaround:

Remove the ssl.root from the zone.

 

Related article:

Technical Tip: Upcoming changes on SSL VPN modes starting from v7.6.3

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!