← Back to knowledge base
high

SSL VPN connections fail when the sslvpnd process is not running

Confirmed 9/18/2026

Problem

SSL VPN users cannot connect to the FortiGate because the `sslvpnd` daemon has not started and is therefore not accepting connections.

Symptoms

- In SSL VPN web mode, the browser reports `ERR_CONNECTION_RESET`, and the login page does not load. - In SSL VPN tunnel mode with FortiClient, the connection stops at 10% and displays: `Unable to establish the VPN connection. The VPN server may be unreachable.` - SSL VPN application debugging produces no output when using: ```text diagnose debug application sslvpn -1 ``` - Debug flow shows the connection being denied with: ```text policy-4294967295 is matched, act-drop ``` - The output from the following command does not include `sslvpnd` in the running process list: ```text diagnose sys top ```

Environment

FortiGate configured for SSL VPN web mode or SSL VPN tunnel mode. Starting with FortiOS v7.6.3, SSL VPN tunnel mode is no longer supported, and SSL VPN web mode is named Agentless VPN.

FortiOS version

v7.6.3

Root Cause

The FortiGate has no administratively enabled firewall policy whose incoming interface is `SSL-VPN tunnel interface (ssl.root)`. This occurs when no applicable policy exists or all such policies are disabled. Without an active policy allowing traffic from `ssl.root`, the `sslvpnd` daemon does not run or listen for incoming SSL VPN connections.

Solution

  1. Confirm whether the sslvpnd process is running:
diagnose sys top

If sslvpnd is absent, continue with the following checks.

  1. Check whether sslvpnd is listening on the configured SSL VPN port. Replace <SSL-VPN Port> with the configured port:
diagnose sys tcpsock | grep <SSL-VPN Port>

For example, on port 443, output before remediation can show only other processes listening:

FortiGate # diagnose sys tcpsock | grep 443
0.0.0.0:443->0.0.0.0:0->state=listen err=0 socktype=2 rma=0 wma=0 fma=0 tma=0 inode=28368 process=293/wad
10.255.1.1:443->0.0.0.0:0->state=listen err=0 socktype=1 rma=0 wma=0 fma=0 tma=0 inode=31637 process=239/fltund
  1. In the GUI, go to Policy & Objects -> Firewall Policy.

  2. Create at least one active firewall policy that permits traffic from SSL VPN tunnel interface (ssl.root) to another interface. For example, create a policy from ssl.root to the LAN network behind port 5. If a suitable policy already exists, ensure that it is administratively enabled.

  3. After the active policy is created or enabled, confirm that the FortiGate starts sslvpnd. Users should then be able to establish the VPN connection.

Verification

  1. Run the process-monitoring command and verify that sslvpnd appears in the running process list:
diagnose sys top
  1. Check the configured SSL VPN port and confirm that sslvpnd is listening. Example for port 443:
diagnose sys tcpsock | grep 443

Expected example output:

FortiGate # diagnose sys tcpsock | grep 443
0.0.0.0:443->0.0.0.0:0->state=listen err=0 socktype=3 rma=0 wma=0 fma=0 tma=0 inode=2641407 process=3148/sslvpnd
0.0.0.0:443->0.0.0.0:0->state=listen err=0 socktype=2 rma=0 wma=0 fma=0 tma=0 inode=28368 process=293/wad
10.255.1.1:443->0.0.0.0:0->state=listen err=0 socktype=1 rma=0 wma=0 fma=0 tma=0 inode=31637 process=239/fltund
  1. Retest the connection using the applicable SSL VPN client or browser and confirm that authentication can proceed.

Tags

No tags yet.

Community rating

— / 5 (0)

Discussion (0)

    No comments yet.