FortiOS 7.6.3 · SSL VPN tunnel mode removed

Your SSL VPN is
being removed.
Your options are
still yours.

FortiOS 7.6.3 replaces SSL VPN tunnel mode with IPsec. Fortinet's release notes are direct about what that means for your configuration: “Settings will not be upgraded from previous versions.” You are rebuilding remote access either way. This is a good moment to decide what you rebuild it on.
G2 logoThe #1 Business VPN
  • Up to 2 connections
  • Free forever
  • No card required
FortiOS 7.6.3 · tunnel mode removed

Trusted by 20,000+ organizations for over two decades.

OrangeTargetSalesforceGoogleHSBCBayerNvidiaAmazonTeslaIBMPWCDeloitteKPMGAccentureDiscordMichelin6Sensebosch logoBoeingEricssonCardinal HealthValvePhilipsGrouponCiscoJamf logoLogitech logo
OrangeTargetSalesforceGoogleHSBCBayerNvidiaAmazonTeslaIBMPWCDeloitteKPMGAccentureDiscordMichelin6Sensebosch logoBoeingEricssonCardinal HealthValvePhilipsGrouponCiscoJamf logoLogitech logo

Backed by enterprise-grade security

Certification SOCSOC 2 Type 2
Certification ISO 27001ISO/IEC 27001:2022
Certification HIPAAHIPAA Compliant
Certification GDPRGDPR Compliant

What actually changed

Tunnel mode is gone in 7.6.3

Fortinet's release notes: “Starting in FortiOS 7.6.3, the SSL VPN tunnel mode feature is replaced with IPsec VPN, which can be configured to use TCP port 443.”

No longer available in the GUI or the CLI, on any model.

FortiOS 7.6.3 release notes

Your configuration does not come with you

“Settings will not be upgraded from previous versions.”

Every SSL VPN policy, portal, and user group is a manual rebuild.

FortiOS 7.6.3 release notes

Smaller models lost more

On the entry and low-RAM models, Agentless VPN is gone from the GUI and CLI as well, and those settings do not upgrade either.

  • 40F
  • 60F
  • 61F
  • FGR-60F 2GB
  • 90G
  • 91G
FortiOS 7.6.3 release notes

Web mode was renamed, not removed

Clientless web mode is now called Agentless VPN. Fortinet: “FortiGate models not listed above will continue to support Agentless VPN.”

It survives everywhere except the models above.

FortiOS 7.6.3 release notes

The free VPN-only client has stopped moving

Fortinet's own release notes for FortiClient Windows 7.4.7: “FortiClient (Windows) 7.4.4 to 7.4.7 do not include a new version of the free VPN-only agent as no feature updates were made to the free VPN-only agent between 7.4.3 and 7.4.7.”

The 7.4.4 notices also record that it “no longer supports IKEv1 for IPsec VPN.”

Fortinet publishes a guide titled “Shifting from standalone VPN-only FortiClient (free) to FortiSASE.”

FortiClient Windows 7.4.7 special notices

The question worth asking

You are being pointed at two destinations: rebuild on IPsec, or move to a subscription service that runs in someone else's cloud.

There is a third. Keep self-hosting, and own the whole thing.

What you get with Access Server

Zero Trust Application Broker

Access Server verifies the user's identity, device and location at connection, then assigns a synthetic intermediate IP scoped to a single authorized application, configured by domain name. The device never receives a route into the private network, so lateral movement is not merely limited — it is structurally impossible. Alongside it, access rules set exactly which subnets, IP addresses, protocols and ports each group reaches.

Mix & match authentication

PAM, RADIUS, LDAP, SAML, local, or custom logic through Python3 post-authentication scripts. MFA via authenticator apps and TOTP. Keep the identity provider you already run.

Self-host anywhere you already run

Ubuntu LTS, Debian, or RHEL. Pre-built images for AWS, Azure, Google Cloud, Oracle Cloud, IBM Cloud and DigitalOcean. Docker, VMware ESXi, Hyper-V. On-premise or in your own VPC — your call, not ours. Control plane and data plane both sit on your infrastructure, with no vendor coordination service in the path.

Kernel acceleration

OpenVPN Data Channel Offload (DCO) moves encryption and decryption into the Linux kernel. Clients do not have to run DCO to connect to a DCO-enabled server.

Pay for connections, not seats

A connection is a device actively connected at the same time as another, so you license your shift rather than your headcount. Deploy as many servers as you need and share one pool of connections across all of them.

Clustering

Active-active nodes for availability and capacity, DNS-distributed, sharing a single subscription. Clients use the same profile across every node.

Every client your fleet runs

Windows, macOS, Linux, ChromeOS, iOS and Android, through the OpenVPN Connect app.

Air-gapped installs supported

Offline activation is available for isolated networks. Contact Support for a fixed licence key.

An open, audited protocol

The OpenVPN protocol is open source and open to scrutiny. So is the implementation.

Every feature above, free for 2 connections.

Instant access. No card required.

Migration is a config rebuild either way

You already have to redo it. The work is comparable — the difference is where you end up.

  1. 1

    Install Access Server

    On a VM, a cloud instance, or hardware you already own.

  2. 2

    Connect your existing directory

    LDAP, RADIUS, or SAML — and keep your groups.

  3. 3

    Define access rules

    By user or group, down to subnet, IP, protocol and port.

  4. 4

    Distribute profiles

    Through the Client Web UI, a bundled installer, a token URL, or your MDM.

Try the world's most-used VPN for secure access

Access Server

From$7/connection/mo

Billed yearly, from 3 connections

  • Self-host anywhere you already run
  • Mix & match authentication
  • Active-active clustering, kernel acceleration
  • Air-gapped installs supported

One plan.
Every feature.

Priced by simultaneous connections, not named users.
Up to 2 connections. Free forever. Instant access to all features. No card required.
Running a larger estate? We offer custom connection packages of 2,000 and above — talk to sales.

Rebuild it on your terms.

Up to 2 connections. Free forever. Instant access to all features. No card required.Get Started for Free