SSL VPN connections fail when the sslvpnd process is not running
Confirmed 9/18/2026
Problem
SSL VPN users cannot connect to the FortiGate because the `sslvpnd` daemon has not started and is therefore not accepting connections.
Symptoms
- In SSL VPN web mode, the browser reports `ERR_CONNECTION_RESET`, and the login page does not load. - In SSL VPN tunnel mode with FortiClient, the connection stops at 10% and displays: `Unable to establish the VPN connection. The VPN server may be unreachable.` - SSL VPN application debugging produces no output when using: ```text diagnose debug application sslvpn -1 ``` - Debug flow shows the connection being denied with: ```text policy-4294967295 is matched, act-drop ``` - The output from the following command does not include `sslvpnd` in the running process list: ```text diagnose sys top ```
Environment
FortiGate configured for SSL VPN web mode or SSL VPN tunnel mode. Starting with FortiOS v7.6.3, SSL VPN tunnel mode is no longer supported, and SSL VPN web mode is named Agentless VPN.
FortiOS version
v7.6.3
Root Cause
The FortiGate has no administratively enabled firewall policy whose incoming interface is `SSL-VPN tunnel interface (ssl.root)`. This occurs when no applicable policy exists or all such policies are disabled. Without an active policy allowing traffic from `ssl.root`, the `sslvpnd` daemon does not run or listen for incoming SSL VPN connections.
Solution
- Confirm whether the
sslvpndprocess is running:
diagnose sys top
If sslvpnd is absent, continue with the following checks.
- Check whether
sslvpndis listening on the configured SSL VPN port. Replace<SSL-VPN Port>with the configured port:
diagnose sys tcpsock | grep <SSL-VPN Port>
For example, on port 443, output before remediation can show only other processes listening:
FortiGate # diagnose sys tcpsock | grep 443
0.0.0.0:443->0.0.0.0:0->state=listen err=0 socktype=2 rma=0 wma=0 fma=0 tma=0 inode=28368 process=293/wad
10.255.1.1:443->0.0.0.0:0->state=listen err=0 socktype=1 rma=0 wma=0 fma=0 tma=0 inode=31637 process=239/fltund
-
In the GUI, go to Policy & Objects -> Firewall Policy.
-
Create at least one active firewall policy that permits traffic from SSL VPN tunnel interface (ssl.root) to another interface. For example, create a policy from
ssl.rootto the LAN network behind port 5. If a suitable policy already exists, ensure that it is administratively enabled. -
After the active policy is created or enabled, confirm that the FortiGate starts
sslvpnd. Users should then be able to establish the VPN connection.
Verification
- Run the process-monitoring command and verify that
sslvpndappears in the running process list:
diagnose sys top
- Check the configured SSL VPN port and confirm that
sslvpndis listening. Example for port 443:
diagnose sys tcpsock | grep 443
Expected example output:
FortiGate # diagnose sys tcpsock | grep 443
0.0.0.0:443->0.0.0.0:0->state=listen err=0 socktype=3 rma=0 wma=0 fma=0 tma=0 inode=2641407 process=3148/sslvpnd
0.0.0.0:443->0.0.0.0:0->state=listen err=0 socktype=2 rma=0 wma=0 fma=0 tma=0 inode=28368 process=293/wad
10.255.1.1:443->0.0.0.0:0->state=listen err=0 socktype=1 rma=0 wma=0 fma=0 tma=0 inode=31637 process=239/fltund
- Retest the connection using the applicable SSL VPN client or browser and confirm that authentication can proceed.
Tags
No tags yet.
Community rating
— / 5 (0)
Discussion (0)
No comments yet.