FortiSASE enforcing IPsec encapsulation over TCP
I know you need to be running v26.1.x in your SASE instance, and all your FortiClients running on 7.4.5, to set your clients VPNs to run connect IPsec over TCP. But in the SASE console I can find only one setting that affects encapsulation: under Endpoint Profiles/Global connection settings. There is one toggle next to FortiSASE Cloud Security Tunnel encapsulation and it's either Auto or UDP. UDP appears to be set as the default. The description of Auto is that the client will try UDP first and then falls back to TCP encapsulation. If you select Auto there is no apparent way to set the TCP port you want to use, and there appears to be no way to just force your clients to use TCP from the start.
We want to force clients to always use IPsec over TCP and to force port 443. Does anyone know if this is currently possible given the versions l listed?
