| Description | The article explains the SSL-VPN Tunnel mode will go through the Proxy PAC file setting. |
| Scope | FortiGate and FortiClient. |
| Solution |
If there is a proxy PAC file configured in the user window environment, when connecting SSL-VPN tunnel via FortiClient, the tunnel mode connection will dynamically load the 'WinHttp.dll' to support proxy.pac file. Bypass the SSL-VPN destination address in the proxy.pac file, if this setting is not required.
To configure the proxy.pac file, refer to Technical Tip : How to configure explicit proxy auto-config (PAC) to bypass traffic.
Note: Starting from FortiOS v7.6.3, the SSL VPN tunnel mode will no longer be supported, and SSL VPN web mode will be called 'Agentless VPN' as explained in Upcoming changes on SSL VPN modes starting from v7.6.3. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.