Hello,
we are preparing the FG90G models to substitute the FG81E cluster. Right now we have 7.4.7 and I was able to enable SSL VPN por CLI. Since we are using 50 FortiTokens (no Cloud Tokens) for the SSL VPN right now I guess we have to transfer them via the Fortinet Support to the new models.
> I guess we cant copy the user with the Tokens to the new model and I am preparing to configure them via LDAP as new users and later assign them the FortiTokens I will get via transfer. I dont think there is a better way, no?
> There will be no more SSL VPN for this model since we tested with 7.4.8 and I could not enable SSL VPN. Since we have to start over with all users because of the Token we will have to change to IPSec and start over with PSK. I dont think there is a better way, no?
> One thing I still have not figured out is the problem with the SSL connection from users behind customer firewalls. So far we have not localized an actual user with this problem but it could be a problem in the future. What can we do with remote access when users are behind systems where they only allow https traffic - any suggestions?
Thanks!
Hi Roland
You can migrate to IPsec or to ZTNA.
BTW I see many companies are migrating to ZTNA since this solution integrates client security and posture as well.
If customer firewall allows only HTTPS traffic then you just need to configure your IPsec or your ZTNA on the 443 TCP port.
You can still transfer Fortitoken licenses to the new devices because you bought them already before the ban starts in Aug. You just need to ask FTNT CS team.
By the way, ZTNA requires EMS, either on-prem or Cloud one and, of course, licenses for the number of clients.
Toshi
User | Count |
---|---|
2431 | |
1304 | |
778 | |
561 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.