Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MORAMADAN
New Contributor III

Regarding disabling SSL VPN tunnel mode

Hello Team,

                 From the links below, I can understand that there won't be support for the SSL VPN tunnel any more starting from software version 7.6.3.

Does this include all platforms? my firewall model is 1801F, we have not deployed the VPN yet but planning in the near months.

and what about countries that do not allow using of the IPsec VPN?

TIA

M.Ramadan
M.Ramadan
4 REPLIES 4
AEK
SuperUser
SuperUser

AEK
kalluka1
New Contributor

No, it won’t. You use a loopback interface for the SSL VPN and create a policy and a VIP for it. That way, you won’t need to disable it from the settings, you can just disable the policy instead.

omegle xender
Toshi_Esumi
SuperUser
SuperUser

What's 7.6.3's document @AEK referred to is saying is you need to use IPsec VPN over TCP like on port 443, just like SSL VPN.
One possible issue is I heard a rumor that IPsec over TCP feature would be dropped with FortiClient VPN (free version without EMS). If that's true you have to have a licensed FortiClient EMS (or the cloud version of EMS) with full version of FortiClient. I'm assuming you can afford that. I'm keenly realizing that's not an option for individual small FGT user though.

Toshi




jay_rich
New Contributor II

You're right, starting from version 7.6.3, Fortinet plans to phase out SSL VPN tunnel mode. This applies across platforms, including your 1801F. If you're in a region where IPsec VPN is restricted, consider checking whether Fortinet will still support SSL VPN in web mode or offer any exceptions. It's best to confirm with Fortinet directly for region-specific policies and alternative secure access options.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors