Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
yeowkm99
Contributor

SSLVPN tunnel mode

We received this notification from our Fortinet support team regarding SSL VPN tunnel mode.

is this referring to SSL VPN for users using forticlient SSLVPN or site-to-site IPSec VPN tunnel ?

We are still using SSLVPN mode in our forticlient VPN.

SSL VPN tunnel mode replaced with IPsec VPN

Starting in FortiOS 7.6.3, the SSL VPN tunnel mode feature is replaced with IPsec VPN, which can be configured to use TCP port 443. SSL VPN tunnel mode is no longer available in the GUI and CLI. Settings will not be upgraded from previous versions. This applies to all FortiGate models.

To ensure uninterrupted remote access, customers must migrate their SSL VPN tunnel mode configuration to IPsec VPN before upgrading to FortiOS 7.6.3 and later.

See Migration from SSL VPN tunnel mode to IPsec VPN in the FortiOS 7.6 New Feature guide for detailed steps on migrating to IPsec VPN before upgrade.

A complete migration guide can be found in the following links:

1 Solution
funkylicious

in a few words, yes.

you would need to start evaluating the IPsec config/setup and plan the migration from SSLVPN to IPsec, but you can still use SSLVPN as long as you are on a version <7.6.3 

"jack of all trades, master of none"

View solution in original post

"jack of all trades, master of none"
5 REPLIES 5
funkylicious
SuperUser
SuperUser

it refers to SSLVPN for clients, IPsec ( site2site, dialup ) is not affected.

"jack of all trades, master of none"
"jack of all trades, master of none"
yeowkm99

so basically we need to change how users uses forticlient VPN to connect remotely ??

funkylicious

in a few words, yes.

you would need to start evaluating the IPsec config/setup and plan the migration from SSLVPN to IPsec, but you can still use SSLVPN as long as you are on a version <7.6.3 

"jack of all trades, master of none"
"jack of all trades, master of none"
yeowkm99

so if i change to IPsec VPN, do i still need the forti-token for the 2FA as i am using in SSLVPN ?

funkylicious

you can still use 2FA even with IPsec

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors