SSL VPN user connect fails from public ipv6
Confirmed 7/20/2026
Problem
when user outside of office tries to connect to company infrastructure through ssl vpn the connection could fail or even connect successfully but no access is possible and no data transmitted in the vpn tunnel.
Environment
FortiGate
FortiOS version
All versions
Root Cause
SSL VPN connection is generated from an IPv6 public ip while fortigate is configured to accept only IPv4.
Solution
By default connecting to ssl vpn from a public ipv6 Address is disabled, to enable it many steps must be taken:
Cli command
config vpn ssl settings
set dual-stack-mode enable
end
In ssl-vpn portals ipv6 Range must be added as source ip pool In ssl-vpn settings under source ip pools ipv6 Range must be addes too In every security policy allowing access from ssl-vpn ipv6 must be added as SRC & DST
Verification
SSL VPN from FortiClient shoulf work and show both IPv4 & IPv6 assigned to the user.
Tags
No tags yet.
Community rating
— / 5 (0)
Discussion (0)
No comments yet.