Created on
04-12-2023
10:24 PM
Edited on
10-08-2025
09:49 PM
By
Anthony_E
This article describes some common errors when configuring SSL VPN on a FortiGate running NGFW policy-based mode.
FortiGate.
Issue 1: SSL VPN is unreachable.
In this example, TCP port 20443 has been configured in SSL VPN settings on the external interface, and the TCP SYN packet reaches the firewall, but it does not respond.
The Local-In Policy list shows no open TCP or UDP 20443 port:
After configuring both items, the SSL VPN will run and listen on the intended port for connection attempts.
Issue 2: Unexpected 'Permission Denied' when using the intended VPN user and password
Verify the intended VPN user or group is referenced in at least one of the following locations:
Issue 3: The User can connect to the VPN, but has no access to the intended resources.
Apart from the requirement to configure appropriate policies in 'Security Policy' and 'SSL Inspection & Authentication', SSL VPN troubleshooting for NGFW policy-based mode is otherwise very similar to profile-based mode.
Related articles:
Troubleshooting Tip: SSL VPN Troubleshooting
Technical Tip: A quick guide to FortiGate SSL VPN authentication and common issues and misunderstandi...
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.