Skip to main content
BruceLiu
Visitor III
January 15, 2025
Question

The Root reasons for Disabling SSL VPN Functionality on Specific Devices

  • January 15, 2025
  • 10 replies
  • 8581 views

Dear Team,
According to the article "Technical Tip: Special Notice for low end units (<2Gb RAM) upgrading to FortiOS 7.4.4 and 7.6.0," or "SSL VPN not supported on FortiGate 90G series models" We understand that FortiGate units with less than 2GB RAM will lose SSL VPN functionality, including the security posture check supported by SSL VPN, when upgrading to newer versions. I would like to inquire about the core reason for this. Will larger models of FortiGate also face this dilemma in the future? Additionally, if larger models also gradually do not support SSL VPN along with the security posture check, what would be the alternative solution?
Regards,
Bruce Liu

 
 

10 replies

AEK
SuperUser
SuperUser
January 15, 2025

Hello Bruce

I don't have the exact answer to your concern, but know that SSL VPN is not secure and is not recommended anymore and should be replaced by ZTNA or IPsec.

AEK
BruceLiu
BruceLiuAuthor
Visitor III
January 15, 2025

Dear AEK,
I would like to understand further, is this an issue based on the SSL VPN protocol or a FortiGate level issue? I see that FortiGate's competitors don't seem to be taking such actions? If you know anything, please share with me, thank you.

Regards,

Bruce Liu

 
pminarik
Staff
Staff
January 15, 2025

SSL-VPN is not a standard protocol, it's rather more of a concept for doing a VPN, by utilizing TLS for tunneling, and optionally pretending to be HTTPS traffic or actually using some HTTPS in the implementation. However, everyone's implementation is different and custom. That is why FortiOS SSL-VPN can only be used by FortiClient, and no other client software (unless it was explicitly coded to be compatible with FortiOS, such as the open-source openfortivpn).

 

TLS and HTTPS are obviously doing well and nobody is planning to decommision those, so SSL-VPN as a concept is perfectly fine as well.

It is just turning out recently that many SSL-VPN implementations have lots and lots of issues...

AEK
SuperUser
SuperUser
January 15, 2025

Hi Bruce

In addition to Minarik's response, I think one of the main reasons for which SSL-VPN is not recommended anymore is that historically there were many critical and high vulnerabilities discovered on SSL-VPN, which just makes it statistically unsafe even if they were patched each time.

You can check here.

https://www.fortiguard.com/search?q=ssl-vpn&engine=1&type=psirt

On the other hand, if I understand well your last question, yes there are third party products that can connect with FortiGate through SSL-VPN (like fortisslvpn plugin) and through IPsec VPN (like strongSwan).

AEK
Hysterical-Networks
New Member
January 19, 2025

@BruceLiu:

 

Of all the responses, @Webspacekit hit the nail on the head, IMO. Fundamentally, supporting SSL-VPN and proxy related features is becoming a resource problem for the lowest end desktop models limited to 2GB of RAM. For those of you who have had a firewall go into conserve mode you know what I am referring to.

 

The company I work for is an Advanced Fortinet partner and in speaking with our Channel Sales Engineer, what I was told is Fortinet is looking to separate the SSL-VPN and proxy engine so that it can be updated outside of FortiOS--similar to how AV and IPS engine receive definition updates. Given the number of zero-day vulnerabilities impacting these features, this makes sense so FTNT can push updates quickly without requiring a FortiOS update.

 

For those of you with remote access users using SSL-VPN on 2GB models, you can either trade-up to a model that has 4GB or more of RAM (70F or higher) or you will want to begin testing IPSec tunnels for remote access VPN, which will still be supported on these 2GB models.

 

Thanks,

Michael C (FCP)

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.