Description | This article describes that a limitation of SSL VPN load balancing exists in FortiGate-6K/7K Chassis. |
Scope | FortiGate-6K/7K Chassis. |
Solution |
SSLVPN support load balance is now supported in most of the latest firmware of FortiGate-6K/7K Chassis:
In certain situations, load balancing cannot be done. For example, in a situation where the DMZ/internal server is a source initiating connection to the destination as an SSL VPN host.
This situation mostly happens in the VoIP environment when the call server receives a call request and forwards it to the target SSL VPN host.
When the chassis's FIM/MBD receives this type of request, then it will forward to a blade by following the load balancing algorithm, and end the traffic may reach a worker FPM/FPC which does not have the SSL VPN setup to the SSL VPN host and caused the connection dropped.
Solution:
Disable load balancing for SSL VPN:
config load-balance setting set sslvpn-load-balance disable end
Create flow rule to master blade:
config load-balance flow-rule |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.