I am using the SSL-VPN tunnel interface (ssl.root) in a zone. But in the vpn ssl configuration it does not detect the policy created using the zone instead of the interface.
There is a document that indicates that this configuration is possible.
But I am trying version 7.0.5 and it does not work.
Here is the zone:
This is the policy:
But in the ssl settings apper the missing policy error:
Has anyone had this problem?
Solved! Go to Solution.
Hi Team,
I have checked again for the web mode as well. It is working both for forticlient and web mode.
Please let me know the firmware version you are using. I will check and keep you posted.
Hi Team,
Yes we are getting that error, But still we are able to connect to SSL VPN.
Make sure to add user in firewall policy in source field along with IP address.
Could you please check and keep us posted.
Hello,
As you can see i have the policy with user group and the ip address that you mention 
but when I try to connect to the vpn from the right realm (it works if I take it out of the zone) I get this error "Error: Permission denied".
I did a packet capture and the traffic arrives correctly, only that for some reason it does not authenticate (I reaffirm, only when it is inside the zone it does not work, when I have the policy without the zone with the ssl interface it works correctly).
I don't know if I have any extra error in my configuration, if you could confirm it, I would be very grateful.
Hi Team,
I have checked again for the web mode as well. It is working both for forticlient and web mode.
Please let me know the firmware version you are using. I will check and keep you posted.
Hi,
Where are using Fortigate 201F 7.0.5 build0304 (GA)
Here is the ssl config in case do u need to look something in specific 
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.