Fortigate SSLVPN client/server will not pass traffic unless "diag firewall iprope flush" is issued.
This is across multiple firewall client types running 7.0.12 and 7.2.5.
The VPN head end is running 7.2.5.
When configuring the fortigate as an SSL VPN Client connecting to another fortigate acting as an SSL VPN concentrator the tunnel will come up but traffic will not pass until the command "diag firewall iprope flush" is issued from CLI. Traffic will immediately start passing as soon as the command is issued.
If the device is rebooted the device will again not be able to pass traffic until the command is run.
I guess this command could be scheduled hourly but I would rather identify the issue so the command does not need to be entered at all.
