FortiOS 7.6.3 · SSL VPN tunnel mode removed
Your SSL VPN is
being removed.
Your options are
still yours.
- Up to 2 connections
- Free forever
- No card required
FortiOS 7.6.3 · SSL VPN tunnel mode removed
Fortinet's release notes: “Starting in FortiOS 7.6.3, the SSL VPN tunnel mode feature is replaced with IPsec VPN, which can be configured to use TCP port 443.”
No longer available in the GUI or the CLI, on any model.
“Settings will not be upgraded from previous versions.”
Every SSL VPN policy, portal, and user group is a manual rebuild.
On the entry and low-RAM models, Agentless VPN is gone from the GUI and CLI as well, and those settings do not upgrade either.
Clientless web mode is now called Agentless VPN. Fortinet: “FortiGate models not listed above will continue to support Agentless VPN.”
It survives everywhere except the models above.
Fortinet's own release notes for FortiClient Windows 7.4.7: “FortiClient (Windows) 7.4.4 to 7.4.7 do not include a new version of the free VPN-only agent as no feature updates were made to the free VPN-only agent between 7.4.3 and 7.4.7.”
The 7.4.4 notices also record that it “no longer supports IKEv1 for IPsec VPN.”
Fortinet publishes a guide titled “Shifting from standalone VPN-only FortiClient (free) to FortiSASE.”
You are being pointed at two destinations: rebuild on IPsec, or move to a subscription service that runs in someone else's cloud.
There is a third. Keep self-hosting, and own the whole thing.
Access Server verifies the user's identity, device and location at connection, then assigns a synthetic intermediate IP scoped to a single authorized application, configured by domain name. The device never receives a route into the private network, so lateral movement is not merely limited — it is structurally impossible. Alongside it, access rules set exactly which subnets, IP addresses, protocols and ports each group reaches.
PAM, RADIUS, LDAP, SAML, local, or custom logic through Python3 post-authentication scripts. MFA via authenticator apps and TOTP. Keep the identity provider you already run.
Ubuntu LTS, Debian, or RHEL. Pre-built images for AWS, Azure, Google Cloud, Oracle Cloud, IBM Cloud and DigitalOcean. Docker, VMware ESXi, Hyper-V. On-premise or in your own VPC — your call, not ours. Control plane and data plane both sit on your infrastructure, with no vendor coordination service in the path.
OpenVPN Data Channel Offload (DCO) moves encryption and decryption into the Linux kernel. Clients do not have to run DCO to connect to a DCO-enabled server.
A connection is a device actively connected at the same time as another, so you license your shift rather than your headcount. Deploy as many servers as you need and share one pool of connections across all of them.
Active-active nodes for availability and capacity, DNS-distributed, sharing a single subscription. Clients use the same profile across every node.
Windows, macOS, Linux, ChromeOS, iOS and Android, through the OpenVPN Connect app.
Offline activation is available for isolated networks. Contact Support for a fixed licence key.
The OpenVPN protocol is open source and open to scrutiny. So is the implementation.
You already have to redo it. The work is comparable — the difference is where you end up.
On a VM, a cloud instance, or hardware you already own.
LDAP, RADIUS, or SAML — and keep your groups.
By user or group, down to subnet, IP, protocol and port.
Through the Client Web UI, a bundled installer, a token URL, or your MDM.
Billed yearly, from 3 connections