Skip to main content
dcschamika
Explorer III
June 15, 2026
Question

Consolidation and comparison of FortiClient Type and respective dependencies to be considered when migrating from SSL-VPN to IPSEC VPN

  • June 15, 2026
  • 0 replies
  • 78 views

Following table outline’s, a set of Dependencies and Key points to be considered and useful with planning a migration of SSL-VPN deployment to IPSEC-VPN based deployment. Below Table is an effort of consolidating the functionalities and capabilities for effective planning of a migration. Content has been extracted from official Fortinet documentations and have put into a table for quick reference. 

FortiClient Version

Dependencies

Free Version - up to client Version 7.4.3

1. User Authentication through Local user database

- IKEv1 - supported with XAUTH framework*

- IKEv2 - Supported with EAP

2. User Authentication through LDAP

- IKEv1- supported with XAUTH framework *

- IKEv2 - Limitations with the way EAP framework operates EAP-TTLS method has to be used. FortiClient Free version has limitations of changing the EAP method. **

3. User Authentication through RADIUS

- IKEv1 - Supported with XAUTH Framework *

- IKEv2 - Supported with EAP-MSCHAPv2

4. User authentication with SAML

- IKEv1 - Not supported

- IKEv2 - Supported (requires the client versions above 7.2.4)

Licensed FortiClient Versions (managed Through EMS)

1. User Authentication through Local user database

- IKEv1 - supported with XAUTH framework *

- IKEv2 - Supported with EAP

2. User Authentication through LDAP

- IKEv1- supported with XAUTH framework *

- IKEv2 - Supported with EAP-TTLS. Changes to the FortiClient XML configuration file via EMS will be required, specifically modifying the EAP authentication method under the IKE settings.

3. User Authentication through RADIUS

- IKEv1 - Supported with XAUTH Framework *

- IKEv2 - Supported with EAP-MSCHAPv2

4. User authentication with SAML

- IKEv1 - Not supported

- IKEv2 - Supported (requires the client versions above 7.2.4)

Remarks

* Starting from FortiClient Version 7.4.4 IKEv1 will be discontinued. FortiClient 7.4.4 does not include a new version of the free VPN-only agent as no feature updates were made to the free VPN-only agent between 7.4.3 and 7.4.4.

**The free FortiClient edition is not supported by Fortinet Technical Assistance and does not receive feature development or updates. (e.g. XML File configurations for Free Version of FortiClient agents). For the operation of this functionality the XML file will required to be edited to make changes with EAP operational framework.

Fortinet Official References

1. EAP-TTLS Compatibility - https://docs.fortinet.com/document/forticlient/7.4.0/new-features/907253/eap-ttls-support-for-ipsec-vpn-7-4-3

2. SAML-Based User Authentications - https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/951346/saml-based-authentication-for-forticlient-remote-access-dialup-ipsec-vpn-clients

3. IKEv2 Dialup with LDAP authentication - https://community.fortinet.com/t5/FortiGate/Technical-Tip-IKEv2-dial-up-VPN-with-LDAP-authentication/ta-p/394380

4. IKEv2 Dialup IPSEC with RADIUS Authentications - https://community.fortinet.com/t5/FortiGate/Technical-Tip-IKEv2-Dialup-IPsec-tunnel-with-RADIUS-and/ta-p/220818