Skip to main content
RolandBaumgaertner72
New Member
June 19, 2025
Question

New FG90G - we need SSL VPN, which FortiOS can I use?

  • June 19, 2025
  • 1 reply
  • 1728 views

Hello,

 

we have to update a FG80E to a new FG90G cluster.

 

We need SSL VPN, mayber later on we can change from SSL VPN to IPSec, but not now in the process of installing the new FG. After reading x posts about the SSL functionality and FG90G someone can tell me 100% with what FortiOS I have the functionality. I updated both of them directly to 7.4.8 without thinking about the SSL (they have 8MB RAM, what the hell????) and now without registering the FGs I cant even downgrade the FortiOS.

 

Thanks,

Roland

1 reply

atakannatak
Explorer
June 19, 2025

Hi @RolandBaumgaertner72 ,

 

Fortinet has removed SSL VPN—both tunnel and web/agentless modes—from all 90G-series firewalls. The feature appeared briefly in early FortiOS 7.4 builds but was reclassified as a withdrawn; current release notes list it as “not supported.” Because every supported FortiOS branch for the FortiGate 90G omits SSL VPN, no lastest firmware version for this model offers the feature. Fortinet advises migrating users to IPsec VPN (which can be configured to run on TCP 443) or choosing another FortiGate model with at least 4 GB of RAM where SSL VPN remains available.

 

https://docs.fortinet.com/document/fortigate/7.6.3/fortios-release-notes/877104/agentless-vpn-formerly-ssl-vpn-web-mode-not-supported-on-fortigate-40f-60f-and-90g-series-models

 

https://docs.fortinet.com/document/fortigate/7.4.8/fortios-release-notes/205987/ssl-vpn-not-supported-on-fortigate-g-series-entry-level-models

 

As far as I know, SSL VPN is still available in FortiOS 7.2.x. However, downgrading a production firewall with an existing configuration can lead to unexpected issues. If you decide to proceed, schedule the work carefully and examine the reference document thoroughly.

 

https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/299518/how-the-fortigate-firmware-license-works

 

BR.

 

If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.

 

CCIE #68781