We received this notification from our Fortinet support team regarding SSL VPN tunnel mode.
is this referring to SSL VPN for users using forticlient SSLVPN or site-to-site IPSec VPN tunnel ?
We are still using SSLVPN mode in our forticlient VPN.
Starting in FortiOS 7.6.3, the SSL VPN tunnel mode feature is replaced with IPsec VPN, which can be configured to use TCP port 443. SSL VPN tunnel mode is no longer available in the GUI and CLI. Settings will not be upgraded from previous versions. This applies to all FortiGate models.
To ensure uninterrupted remote access, customers must migrate their SSL VPN tunnel mode configuration to IPsec VPN before upgrading to FortiOS 7.6.3 and later.
See Migration from SSL VPN tunnel mode to IPsec VPN in the FortiOS 7.6 New Feature guide for detailed steps on migrating to IPsec VPN before upgrade.
A complete migration guide can be found in the following links:
For FortiOS 7.6, see SSL VPN to IPsec VPN Migration.
For FortiOS 7.4, see SSL VPN to IPsec VPN Migration.
Solved! Go to Solution.
in a few words, yes.
you would need to start evaluating the IPsec config/setup and plan the migration from SSLVPN to IPsec, but you can still use SSLVPN as long as you are on a version <7.6.3
it refers to SSLVPN for clients, IPsec ( site2site, dialup ) is not affected.
so basically we need to change how users uses forticlient VPN to connect remotely ??
in a few words, yes.
you would need to start evaluating the IPsec config/setup and plan the migration from SSLVPN to IPsec, but you can still use SSLVPN as long as you are on a version <7.6.3
so if i change to IPsec VPN, do i still need the forti-token for the 2FA as i am using in SSLVPN ?
you can still use 2FA even with IPsec
| User | Count |
|---|---|
| 2712 | |
| 1416 | |
| 810 | |
| 733 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.