Skip to main content
Paaaaaaow
Visitor III
May 22, 2025
Question

SSL VPN over 5G Hotspot: Why Is IPv6 Traffic Bypassing the Tunnel Without a Policy

  • May 22, 2025
  • 2 replies
  • 1064 views

Hi everyone,

I’m trying to understand how FortiGate SSL VPN handles IPv6 traffic when connecting through a mobile hotspot (e.g., 5G tethering).
I’ve noticed some unexpected behavior and would appreciate clarification on how to properly control traffic routing.

 

Here’s my current setup:

SSL VPN is configured with split tunneling disabled

No ssl.root → wan policy is configured

The client connects through a 5G hotspot

Despite no outbound policy, the client can still access external websites

The public IP shown is my 5G IPv6 address, not the company's public IPv4 address

 

Questions:
When connecting to SSL VPN over a 5G hotspot, is traffic routed only through IPv6?

Is it possible to configure FortiGate so that IPv4 traffic works properly over SSL VPN even when connected via a hotspot?

If no outbound policy is configured, why does IPv6 traffic still bypass the tunnel and reach external websites?

Any insights or configuration advice would be greatly appreciated. Thanks in advance!

2 replies

Anthony_E
Staff
Staff
May 26, 2025

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Anthony_E
Staff
Staff
May 27, 2025

Hello,

 

The IPv6 traffic may bypass the SSL VPN tunnel over a 5G hotspot without a policy due to configurations like split tunneling or vulnerabilities that allow traffic to be rerouted. Proper configuration and security measures are necessary to manage this behavior.

 

Hope it helps.

 

Regards,

Anthony

Best Regards
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!