FortiOS 7.6 Removed SSL VPN on Small FortiGates

Do not upgrade a small FortiGate to FortiOS 7.6 if staff still use SSL VPN (FortiClient tunnel). On 2 GB memory models, SSL VPN is removed from 7.6.0. From 7.6.3, tunnel mode is deprecated on every model, and the tunnel config does not survive the upgrade. Move remote users to IPsec before you upgrade. The firewall itself keeps working. Remote access is what breaks.

Megatron Technology Pte Ltd, Singapore. We size and supply Fortinet.

Related pages: Fortinet · FortiGate vs Meraki MX for Singapore offices · FortiGate conserve mode on small units · Knowledge base

What actually changed?


SSL VPN changes a buyer must not mix up
Change Who it hits What you lose
FortiOS 7.6.0 and later Listed 2 GB-class F-series: 40F, 60F, 61F, and the named Wi-Fi and rugged twins SSL VPN entirely. It still exists on 7.4 and earlier on those models
FortiOS 7.6.3 and later All FortiGate models SSL VPN tunnel mode. FortiClient uses tunnel mode. Config is not kept
Entry G-series (90G / 91G and lower) Those models SSL VPN is not supported. Do not plan a new remote-access design on it

Fortinet’s tip: if FortiClient SSL VPN is in use, migrate to another remote-access method, such as IPsec, before the upgrade. After the jump you cannot turn tunnel mode back on.

Web mode is a different feature. From 7.6.3, where it still exists, Fortinet renames it Agentless VPN. That is not a FortiClient laptop tunnel. Do not tell staff “web mode will cover the laptops.”

What should you do before the maintenance window?


Before you move a FortiGate to 7.6
Step Why
List who still uses SSL VPN (FortiClient, bookmarks, vendors) The upgrade does not migrate them
Stand up IPsec (or the remote-access method you will keep) and test one user Fortinet’s recommended path
Confirm the model against the technical tip, not a blog list 40F / 60F lose SSL VPN at 7.6.0; larger boxes lose tunnel mode at 7.6.3
Read the supported upgrade path for that serial Skipping builds is a separate failure. Use Fortinet’s path tool
Only then upgrade Tunnel config is not retained

Staying on a supported 7.4 train is a valid buyer decision if SSL VPN is needed. It is a temporary measure until 7.4 reaches end of life. Fortinet’s tip says later 7.2 and 7.4 releases are not expected to remove SSL VPN on those F-series models. Plan the move anyway.

FAQ

Does this affect the office internet?

No. This is remote-access VPN. Branch internet and site-to-site IPsec continue to be supported. Only SSL VPN is removed.

Can we re-enable SSL VPN after the upgrade?

Not tunnel mode, once you are on 7.6.3 or later. On a 40F or 60F, not at all from 7.6.0. The option entirely disappears when upgraded to 7.6.

Is this the same as conserve mode?

No. Conserve mode is low memory. This is a feature Fortinet removed. A small box can hit both when moving from 7.4 to 7.6 (SSL VPN is removed, but larger engine footprints cause conserve mode to trigger).

Send the model, current FortiOS version, and whether FortiClient SSL VPN is still in use. Megatron Technology will say migrate first or stay on the current train — before a weekend upgrade locks staff out.

Request a migration check: www.megatron.com.sg/fortinet · Contact

Megatron Technology Pte Ltd (est. 1990, UEN 199002644W) is a Singapore Cisco Networking Partner and Managed Services Provider, and a Fortinet reseller. We design, size, licence, procure, deploy and support Cisco Meraki, FortiGate, and Cisco Catalyst & Data Centre from 2 Kallang Avenue #08-17 CT Hub, Singapore 339407.

john francisco