| Description | This article describes SSLVPN connection fails after changing listening interface for SSL VPN settings. | 
| Scope | FortiGate. | 
| Solution | 
 Even after changing the listening interface from the GUI's SSL VPN settings, the previous interface that was listening for SSL VPN connections may still be bound to authentication-rules (for instance, the listening interface was changed from WAN1 to WAN2). In the following configuration, it still shows WAN1 in authentication-rule settings. 
 
 
 A potential problem may exist in the authentication rules within the SSL VPN settings. These settings are only configurable via the CLI. Execute the following commands to verify any issues: 
 Error: If FortiGate responds, when the TCP 3-way handshake does not complete or the client resets the connection after TCP 3-way handshake completes, the connection will terminate and FortiClient will display it stopped at 10%. 
 FortiGate-A (1) # config authentication-rule FortiGate-A (1) # edit 1 FortiGate-A (1) # get 
 
 Note: If there are multiple authentication rules configured (for example, rule 1 is configured to listen on WAN1 and rule 2 is configured to listen on WAN2), users will be able to connect. The connection will only fail if all or only 1 authentication rule is configured with incorrect interface. For example, the following two rules are configured: 
 FortiGate-A (1) # config vpn ssl settings FortiGate-A (authentication-rule) # get 1 
 
 To change this, execute the following commands: 
 
 As this value is not shown in the GUI, it is recommended is to unset the value and set the source interfaces in the generic SSL VPN settings. Troubleshooting Tip: Useful commands for troubleshooting SSL VPN  | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.