Description | This article describes an issue where users are unable to connect to SSL VPN when the ssl.root interface is assigned to a zone. |
Scope | FortiGate v7.4.6, v7.4.7, v7.6.2. |
Solution |
When ssl.root interface is added to a zone, SSL VPN connections fail.
config system zone SSL VPN debug logs may not display any output at the time of the issue. Additionally, the SSL VPN daemon (sslvpnd) process may be failing to start.
This issue has been resolved in v7.6.3.
Starting from v7.6.3, SSL VPN tunnel mode is no longer supported. This applies to all FortiGate models.
Remove the ssl.root from the zone.
Related article: Technical Tip: Upcoming changes on SSL VPN modes starting from v7.6.3 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.