← Back to knowledge base
high

Troubleshooting FortiGate SSL VPN connectivity, authentication, stability, and performance

Confirmed 9/19/2026

Problem

This article provides a structured workflow for diagnosing FortiGate SSL VPN problems, including an unreachable SSL VPN URL, authentication failures, connection stalls at 48% or 98%, immediate tunnel disconnections, incorrect address assignment, implicit-deny drops, MTU problems, and poor throughput.

Symptoms

Typical symptoms include no response from the SSL VPN URL, failed user or SAML authentication, error `Credential or SSL VPN configuration is wrong (-7200)`, negotiation stopping at 48% or 98%, tunnel mode disconnecting after several seconds, assignment from the wrong IP pool, traffic matching implicit deny, communication failing across a lower-MTU path, or slow SSL VPN throughput and file transfers.

Environment

FortiGate SSL VPN using FortiClient, including local or remote authentication, SAML authentication, web mode, tunnel mode, multiple Internet interfaces such as SD-WAN, and DTLS. SSL VPN GUI visibility changes apply beginning with FortiOS v7.4. Hardware and model restrictions apply to devices with 2 GB RAM or less and to FortiGate 50G, 70G, and 90G models. Starting with FortiClient v7.4.4, IKEv1 is no longer supported; use IKEv2 when planning IPsec migration for FortiClient v7.4.4 and later.

FortiOS version

FortiOS v6.4, v7.0, v7.2, v7.4, through v7.6.2. Additional details also cover v5.4 and later, v6.0.0 or earlier, v6.0.1 or later, v7.2.1+, v7.2.6+, v7.2.12, v7.4.1+, v7.4.8, v7.6.0+, and v7.6.3+.

Root Cause

Possible causes include an SSL VPN port conflict with administrative HTTPS or a Virtual IP; restricted access; an incorrect firewall policy; an incorrect URL, port, FQDN resolution, or local-in policy; `ssl.root` being down; incompatible FortiClient and FortiOS versions; disabled TLS protocols; an exhausted SSL VPN IP pool; packets not reaching FortiGate; bad credentials or two-factor authentication; excessive login latency; asymmetric routing across multiple WAN interfaces; conflicting portal and global IP pools; incorrect user-group policy membership; a reduced path MTU; TCP-in-TCP retransmissions; brute-force login activity consuming resources; client-side IPv6; or SSL VPN being unsupported by the selected firmware or hardware.

Solution

  1. Confirm that SSL VPN is supported before troubleshooting.
    • In FortiOS v7.6.0 and later, physical FortiGate devices with 2 GB RAM or less do not support SSL VPN tunnel or web mode.
    • Check installed memory:
diagnose hardware sysinfo conserve

Example output identifying a device with less than 2000 MB of RAM:

memory conserve mode: off
total RAM: 1917 MB
memory used: 1028 MB 53% of total RAM
memory freeable: 323 MB 16% of total RAM
memory used + freeable threshold extreme: 1821 MB 95% of total RAM
memory used threshold red: 1687 MB 88% of total RAM
memory used threshold green: 1572 MB 82% of total RAM
  • In FortiOS v7.6.3 and later, SSL VPN tunnel mode is unsupported on every FortiGate model. SSL VPN web mode is renamed Agentless VPN in these releases.
  • SSL VPN support for FortiGate 50G, 70G, and 90G was removed beginning with FortiOS v7.2.12 and v7.4.8.
  • If remote access depends on SSL VPN, migrate to IPsec VPN before upgrading to firmware that removes SSL VPN tunnel mode. FortiClient v7.4.4 and later does not support IKEv1, so use IKEv2 when planning such a deployment.
  1. Enable focused SSL VPN debugging. Reset previous debug settings, filter on the FortiClient public IPv4 address, and enable detailed SSL VPN output:
diagnose debug disable
diagnose debug reset
diagnose vpn ssl debug-filter src-addr4 x.x.x.x
diagnose debug application sslvpn -1
diagnose debug console timestamp enable
diagnose debug enable

Replace x.x.x.x with the connecting user's public IP. The filter limits output to that client. Display available filter parameters with:

diagnose vpn ssl debug-filter ?

Available options are clear to erase the filter, list to display it, src-addr4 for an IPv4 source range, src-addr6 for an IPv6 source range, vd for a virtual-domain name, and negate to invert the selected filter parameter. Clear the filter with:

diagnose vpn ssl debug-filter clear

Successful negotiation can resemble:

[282:root]SSL state:before/accept initialization (172.20.120.12)
[282:root]SSL state:SSLv3 read client hello A (172.20.120.12)
[282:root]SSL state:SSLv3 write server hello A (172.20.120.12)
[282:root]SSL state:SSLv3 write change cipher spec A (172.20.120.12)
[282:root]SSL state:SSLv3 write finished B (172.20.120.12)
[282:root]SSL state:SSLv3 flush data (172.20.120.12)
[282:root]SSL state:SSLv3 read finished A:system lib(172.20.120.12)
[282:root]SSL state:SSLv3 read finished A (172.20.120.12)
[282:root]SSL state:SSL negotiation finished successfully (172.20.120.12)
[282:root]SSL established: DHE-RSA-AES256-SHA SSLv3 Kx=DH Au=RSA Enc=AES(256) Mac=SHA1

Here, 282 is the process ID and root is the VDOM.

  1. Capture authentication debugging when required. Reset existing debugging before starting another capture:
diagnose debug reset

For remote-user authentication issues, run:

diagnose debug application fnbamd -1
diagnose debug enable

For SAML authentication issues, run:

diagnose debug application samld -1
diagnose debug application eap_proxy -1
diagnose debug enable

Stop and reset debugging after collecting the logs:

diagnose debug disable
diagnose debug reset
  1. If the SSL VPN URL does not respond, validate listener and access settings.
    • Verify that the SSL VPN port differs from the administrative access port under System -> Settings -> Administration Settings.
    • Starting with v7.4, SSL VPN GUI visibility is disabled by default. If web and tunnel modes were configured before upgrading to FortiOS v7.4.1 or later, VPN -> SSL-VPN and web-mode settings remain visible. Otherwise, open System -> Feature Visibility and enable SSL VPN.
    • Open VPN -> SSL-VPN Settings and confirm that the assigned port does not conflict with HTTPS or any Virtual IP.
    • Review restricted access and ensure the connecting host is permitted.
    • Check Policy & Objects -> Firewall Policy and verify the SSL VPN policy. From v7.6.x onward, the User/Group option is in a separate dedicated field.
    • Use https://<FortiGate FQDN or IP>:<SSL VPN port> and confirm the URL contains the configured port.
    • Confirm that the FortiGate is reachable. Ping <FortiGate IP> if PING is enabled on the FortiGate interface.
    • Ensure the browser enables TLS 1.1, TLS 1.2, and TLS 1.3.
    • If using an FQDN, verify that it resolves to the correct FortiGate IP address.
    • Inspect local-in policies:
show firewall local-in-policy
  • Confirm that ssl.root is up. If show full reports it down, set its status to up:
config system interface
    edit ssl.root
        show full
        set status up
    next
end
  1. If FortiClient cannot establish the connection, check compatibility, TLS, addressing, and packet arrival.
    • Review the Release Notes and confirm that the FortiClient version is compatible with the installed FortiOS version.
    • FortiClient uses Internet Explorer security settings. Under IE Internet options -> Advanced -> Security, enable Use TLS 1.1 and Use TLS 1.2.
    • Verify that the SSL VPN ip-pools contain free addresses. The default SSLVPN_TUNNEL_ADDR1 range contains 10 IP addresses.
    • In FortiClient, go to File -> Settings. In Logging, enable Export logs, set Log Level to Debug, and select Clear logs. Reproduce the connection error, then select Export logs.
    • Verify that connection packets reach the FortiGate:
diagnose sniffer packet any 'port XXXXX and host y.y.y.y' 4 0 l

Replace XXXXX with the SSL VPN port, such as 10443, and y.y.y.y with the user's public IP. If no packets appear, investigate the client network, modem port forwarding, and ISP.

  1. If negotiation stops or disconnects at 48%, investigate authentication.

    • A stall at 48% generally indicates authentication or two-factor authentication trouble.
    • If FortiClient reports Credential or SSL VPN configuration is wrong (-7200), verify the submitted credentials and SSL VPN configuration.
  2. If negotiation stops or disconnects at 98%, account for driver compatibility and latency.

    • FortiClient v5.6.0 and later includes a newer SSL VPN driver intended to resolve connection issues. Upgrade to a compatible version where FortiOS compatibility permits.
    • Long latency can cause FortiGate to time out before DNS lookup or token entry is complete. In v5.6.0 and later, increase the login and DTLS hello timeouts:
config vpn ssl settings
    set login-timeout 180
    set dtls-hello-timeout 60
end

The default login-timeout is 30; the default dtls-hello-timeout is 10.

  1. If tunnel mode disconnects after a few seconds on a multi-WAN or SD-WAN system, preserve the session path. Multiple Internet interfaces can make the session dirty.
    • For v6.0.1 or later, enable session-route preservation on the applicable interface:
config system interface
    edit <name>
        set preserve-session-route enable
    next
end

preserve-session-route keeps that session on the same WAN interface when network changes occur.

  • For v6.0.0 or earlier, use:
config vpn ssl settings
    set route-source-interface enable
end
  1. If users receive addresses from the wrong pool, align portal and global settings. Open VPN -> SSL-VPN Portals and VPN -> SSL-VPN Settings, then configure the same IP pool in both locations. If pools conflict, the portal setting takes precedence.

  2. If SSL VPN traffic hits implicit deny, verify the authenticated group and policy. Ensure the user belongs to the intended group and that the same group is configured on the target SSL VPN firewall policy. Find the session by client public IP and review all logged-in SSL VPN users:

get vpn ssl monitor | grep <PC Public IP>
get vpn ssl monitor

Example monitor output:

SSL-VPN Login Users:
|Index|User|Group|Auth Type|Idle-Timeout|Auth-Timeout|From|HTTP in/out|HTTPS in/out|Two-factor Auth|
|0|nathan_1|Local_Group|1(1)|243|28743|172.xxx.xxx.xxx|0/0|0/0|0|

Locate policies using ssl.root:

show firewall policy | grep ssl.root -f

The group in the policy must match the authenticated group, as in this example:

config firewall policy
    edit 7
        set name "SSLVPN"
        set srcintf "ssl.root"
        set dstintf "port2"
        set action accept
        set srcaddr "all"
        set dstaddr "10.218.0.0_24"
        set schedule "always"
        set service "ALL"
        set groups "Local_Group"
    next
end
  1. Test for a lower path MTU. First prevent fragmentation by setting the DF bit, then ping the destination:
execute ping-options df-bit yes
execute ping <destination-ip>

Set df-bit to yes to prevent ICMP fragmentation or no to allow it. Then test a smaller payload:

execute ping-options data-size 1472
execute ping <destination-ip>
  1. Improve slow SSL VPN throughput with DTLS where supported. DTLS is available in FortiOS v5.4 and later. It encrypts traffic with TLS while using UDP rather than TCP, avoiding TCP-in-TCP retransmission issues.
  • FortiClient v5.4.0 through v5.4.3 uses DTLS by default.
  • FortiClient v5.4.4 and later uses normal TLS regardless of the FortiGate DTLS setting.
  • In FortiClient, open Settings and enable Preferred DTLS Tunnel.
  • Enable the FortiGate DTLS tunnel:
config vpn ssl settings
    set dtls-tunnel enable
end

This is the default SSL VPN setting.

  1. Reduce performance impact from repeated failed logins. Excessive brute-force attempts can consume resources and reduce throughput. Restrict SSL VPN access to selected countries, disable web mode when it is not required, or automatically block failed logins with an automation stitch. Automation may also block legitimate users who repeatedly enter incorrect credentials.

  2. Review SSL VPN runtime information and statistics. Run the command with the appropriate parameter:

diagnose vpn ssl [list/info/statistics/debug-filter/hw-acceleration-status]

Use list for active connections, info for general information, statistics for memory usage plus concurrent and maximum connections, and hw-acceleration-status for hardware-acceleration status.

  • SSL VPN hardware acceleration was removed in v7.2.1 and later.
  • Starting with v7.2.6+, these options are available:
[list/mux/mux-stat/statistics/tunnel-test/web-mode-test/saml-metadata/info/blocklist/debug-filter/client]
  • Starting with v7.4.1+, these options are available:
[list/mux/mux-stat/statistics/tunnel-test/web-mode-test/saml-metadata/info/blocklist/dist-usr/peer-name/usr-chg/debug-filter/client]
  1. If the preceding checks do not resolve the issue, test with Windows IPv6 disabled.

  2. Press Win + R, enter ncpa.cpl, and press Enter.

  3. Right-click the active network adapter and select Properties.

  4. Locate Internet Protocol Version 6 (TCP/IPv6).

  5. Clear its checkbox.

  6. Select OK, then restart the connection or computer so the change takes effect.

  7. For slow file transfers specifically, continue with SSL VPN slow-file-transfer diagnostics after completing the general throughput checks.

Verification

Confirm that the client can open the configured SSL VPN URL and complete authentication, and that the tunnel remains connected. In SSL VPN debug output, look for SSL negotiation finished successfully followed by SSL established. Verify that the user appears under get vpn ssl monitor, belongs to the group configured on the SSL VPN firewall policy, receives an address from the intended pool, and can pass traffic without implicit-deny matches. The packet sniffer should show traffic arriving on the configured SSL VPN port. For performance cases, compare throughput after enabling Preferred DTLS Tunnel and confirm the required runtime status with diagnose vpn ssl statistics or connection options.

Rollback

After log collection, stop and clear debugging with:

diagnose debug disable
diagnose debug reset

Clear an SSL VPN debug filter with:

diagnose vpn ssl debug-filter clear

For temporary Windows testing, re-enable Internet Protocol Version 6 (TCP/IPv6) after the test if disabling it does not change the behavior. Other configuration changes should be reverted to their previous values if they do not resolve the issue.

Tags

No tags yet.

Community rating

— / 5 (0)

Discussion (0)

    No comments yet.