Skip to main content
systemgeek
Visitor III
April 15, 2025
Solved

ZTNA using SSL VPN

  • April 15, 2025
  • 2 replies
  • 1655 views

I know Fortinet is doing away with SSL VPN.  I am close to moving off SSL VPN and going to Dialup IPSec VPN.  However, its taking a while due to issues I am working with support on.  At the same time I am trying to get my head around ZTNA and from what I have been reading ZTNA uses SSL VPN too but in a more secure way.

 

Please tell me that ZTNA using SSL VPN is NOT going to be going away any time soon????  I am looking to use ZTNA so users can access internal websites on port 443, SSH to hosts, RDP to hosts.  I know there are different methods for each of these.  I just want to make I am not wasting my time by setting this up with ZTNA.

Best answer by atakannatak

Hi @systemgeek ,

 

Fortinet is not planning to drop ZTNA support from FortiOS based on the Fortinet’s roadmap and recent releases (7.2, 7.4, 7.6) have added more ZTNA capabilities, not reduced them. In fact, ZTNA is one of the core strategic feature they are actively investing in. If anything changes (e.g. ZTNA moving to a separate license SKU), it would likely affect licensing or architecture, not the existence of ZTNA itself.

 

So basically you’re safe investing in ZTNA policies — it's not a dead-end.

 

BR.

 

If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.

 

CCIE #68781

2 replies

atakannatak
Explorer
April 16, 2025

Hi @systemgeek ,

 

Fortinet is not planning to drop ZTNA support from FortiOS based on the Fortinet’s roadmap and recent releases (7.2, 7.4, 7.6) have added more ZTNA capabilities, not reduced them. In fact, ZTNA is one of the core strategic feature they are actively investing in. If anything changes (e.g. ZTNA moving to a separate license SKU), it would likely affect licensing or architecture, not the existence of ZTNA itself.

 

So basically you’re safe investing in ZTNA policies — it's not a dead-end.

 

BR.

 

If my answer provided a solution for you, please mark the reply as solved it so that others can get it easily while searching for similar scenarios.

 

CCIE #68781

systemgeek
Visitor III
April 16, 2025

Thank you.  So if I cannot get Dialup IPsec working very soon I will pivot to ZTNA even in a basic form sooner then latter.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!