Description | This article describes what are the downsides of using SSL VPN web mode compared to tunnel mode. |
Scope | FortiGate v6.4.X, v7.0.X, v7.2.X, v7.4.X. |
Solution |
Some years ago most of the web pages were using static HTML. It is relatively straightforward to locate the URL link in static HTML pages and replace/modify it with a pre-defined domain name and URL prefix.
That makes it more difficult to locate the URL in the returned page from HTTPS servers.
The way to get out of this situation and avoid any future problems:
ZTNA access proxy allows users to securely access resources through an SSL-encrypted proxy. This makes remote access much easier by eliminating the use of any sort of VPN tunnel.
In addition to that, the ZTNA rules add a level of security and posture checking.
Note: From v7.6.0, the SSL VPN function has been removed from models with 2GB of RAM: SSL VPN removed from 2GB RAM models for tunnel and web mode
Starting from v7.6.3, the SSL VPN tunnel mode will no longer be supported for all FortiGate models, and SSL VPN web mode will be called 'Agentless VPN'. Agentless VPN (formerly SSL VPN web mode) not supported on FortiGate 40F, 60F, and 90G series models
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.