Skip to main content
bmduncan33
New Member
March 14, 2026
Question

FortiSASE enforcing IPsec encapsulation over TCP

  • March 14, 2026
  • 1 reply
  • 434 views

I know you need to be running v26.1.x in your SASE instance, and all your FortiClients running on 7.4.5, to set your clients VPNs to run connect IPsec over TCP.  But in the SASE console I can find only one setting that affects encapsulation:  under Endpoint Profiles/Global connection settings.  There is one toggle next to FortiSASE Cloud Security Tunnel encapsulation and it's either Auto or UDP.  UDP appears to be set as the default.  The description of Auto is that the client will try UDP first and then falls back to TCP encapsulation.  If you select Auto there is no apparent way to set the TCP port you want to use, and there appears to be no way to just force your clients to use TCP from the start.

 

We want to force clients to always use IPsec over TCP and to force port 443.  Does anyone know if this is currently possible given the versions l listed?

1 reply

btan
Staff & Editor
Staff & Editor
March 15, 2026

Hi @Anonymous_User

As per check internally, enforcing TCP 443 only is not possible at this time. We do have roadmap and internal discussion on this, but there is no ETA commitment yet.
Unfortunately your requirement is not able to be fulfilled at this time, thank you.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!