Skip to main content
yeowkm99
New Member
October 31, 2025
Solved

SSLVPN tunnel mode

  • October 31, 2025
  • 1 reply
  • 1158 views

We received this notification from our Fortinet support team regarding SSL VPN tunnel mode.

is this referring to SSL VPN for users using forticlient SSLVPN or site-to-site IPSec VPN tunnel ?

We are still using SSLVPN mode in our forticlient VPN.

SSL VPN tunnel mode replaced with IPsec VPN

Starting in FortiOS 7.6.3, the SSL VPN tunnel mode feature is replaced with IPsec VPN, which can be configured to use TCP port 443. SSL VPN tunnel mode is no longer available in the GUI and CLI. Settings will not be upgraded from previous versions. This applies to all FortiGate models.

To ensure uninterrupted remote access, customers must migrate their SSL VPN tunnel mode configuration to IPsec VPN before upgrading to FortiOS 7.6.3 and later.

See Migration from SSL VPN tunnel mode to IPsec VPN in the FortiOS 7.6 New Feature guide for detailed steps on migrating to IPsec VPN before upgrade.

A complete migration guide can be found in the following links:

Best answer by funkylicious

in a few words, yes.

you would need to start evaluating the IPsec config/setup and plan the migration from SSLVPN to IPsec, but you can still use SSLVPN as long as you are on a version <7.6.3 

1 reply

funkylicious
SuperUser
SuperUser
October 31, 2025

it refers to SSLVPN for clients, IPsec ( site2site, dialup ) is not affected.

"jack of all trades, master of none"
yeowkm99
yeowkm99Author
New Member
October 31, 2025

so basically we need to change how users uses forticlient VPN to connect remotely ??

funkylicious
SuperUser
SuperUser
October 31, 2025

in a few words, yes.

you would need to start evaluating the IPsec config/setup and plan the migration from SSLVPN to IPsec, but you can still use SSLVPN as long as you are on a version <7.6.3 

"jack of all trades, master of none"