Kernaali Tools
FortiGate

FortiGate SSL VPN Support Matrix by Model and FortiOS Version

Find your FortiGate’s last tunnel-capable FortiOS release and the upgrade that removes it.

FortiOS 7.6.3 removes FortiClient SSL VPN from all FortiGate models. Some models lose it earlier. Release notice.

On this page, SSL VPN means FortiClient SSL VPN tunnel mode. Fortinet renamed the browser-based SSL VPN web mode to Agentless VPN starting with FortiOS 7.6.3.

  • ✓ Yes — FortiClient SSL VPN works
  • ◐ Web mode only — browser access, no FortiClient SSL VPN
  • ✕ No — neither SSL VPN nor web mode
  • — Not supported — firmware cannot run on the model
F/G series · FortiOS version
Model7.27.47.6.27.6.3+8.0Last SSL VPN
40F✓ Yes✓ Yes✕ NoFrom 7.6.0✕ No✕ No7.4.x
60F / 61F✓ Yes✓ Yes✕ NoFrom 7.6.0✕ No✕ No7.4.x
70F / 71F✓ Yes✓ Yes✓ Yes◐ Web mode only◐ Web mode only7.6.2
80F / 81F✓ Yes✓ Yes✓ Yes◐ Web mode only◐ Web mode only7.6.2
100F / 101F✓ Yes✓ Yes✓ Yes◐ Web mode only◐ Web mode only7.6.2
30G / 31G✕ NoNever supported on any available FortiOS releaseNever supported
50G / 51G✕ NoNever supported on any available FortiOS releaseNever supported
70G / 71G✓ YesModel-specific builds✕ NoFrom 7.4.8— Not supported✕ No✕ No7.2.x
90G / 91G✓ YesThrough 7.2.11✕ NoFrom 7.2.12✓ YesThrough 7.4.7✕ NoFrom 7.4.8✕ NoAlready absent in 7.6.1✕ No✕ No7.2.11 / 7.4.7
120G / 121G✓ Yes✓ Yes✓ Yes◐ Web mode only◐ Web mode only7.6.2

Version notation: 7.4.x means no removal patch is documented within that branch for the model. 7.6.2 is the last SSL VPN patch on the 7.6 branch; eligible models still retain SSL VPN on 7.4. Exact patch cutoffs are shown above.

Cells apply to available model builds. Model guidance · 7.6.0 removal · 7.4.8 removal · 7.2.12 issue 1026775 · 8.0 web mode availability.

Legacy E-series FortiOS ceiling

These models still have SSL VPN on their final supported branch. Newer firmware cannot be installed; this is a hardware ceiling, not SSL VPN removal.

ModelNewest FortiOS branchSSL VPN on that branchPractical note
30E6.2✓ Yes6.2.17 verified6.4+ cannot run on this hardware.6.2 models · 6.4 models · SSL CLI
50E / 51E6.2✓ Yes6.2.17 verified6.4+ cannot run on this hardware.6.2 models · 6.4 models · SSL CLI
60E / 61E7.4✓ Yes7.4.12 verified7.6+ cannot run on this hardware.7.4 models · 7.6 models · SSL CLI
80E / 81E7.4✓ Yes7.4.12 verified7.6+ cannot run on this hardware.7.4 models · 7.6 models · SSL CLI
90E / 91E7.4✓ Yes7.4.12 verified7.6+ cannot run on this hardware.7.4 models · 7.6 models · SSL CLI
100E / 101E7.2✓ Yes7.2.12 verified7.4+ cannot run on this hardware.7.2 models · 7.4 models · SSL CLI

Last verified against Fortinet documentation: . 30 models / 16 families.

All F/G families above can run FortiOS 8.0, but not every patch exists for every variant. Use the exact model image and supported upgrade path; FortiClient, endpoint OS and authentication compatibility still matter. FortiWiFi/DSL/POE variants follow the cited notices; Rugged models need an exact RAM/revision check.

SSL VPN web mode, Agentless VPN and IPsec

Web mode provides browser/clientless access. A “Web mode only” result means FortiClient SSL VPN will not connect. Dial-up IPsec VPN is Fortinet’s primary replacement for the FortiClient tunnel. Fortinet’s terminology and model guidance.

FortiGate 40F and 60F SSL VPN support

FortiGate 40F, 60F and 61F lose both SSL VPN and web mode at 7.6.0 because of the affected-model memory restriction. They retain SSL VPN on 7.4.x (7.4.12 checked); they do not get web mode in 8.0.

The 7.6.0 notice also covers FortiWiFi variants and FGR-60F (2 GB and 4 GB). Settings are not upgraded. The later 7.6.5 web-mode notice limits its FGR-60F exclusion to 2 GB versions, while the 8.0 CLI excludes the listed FGR-60F revisions. For a 4 GB Rugged unit, check the exact target release.

FortiGate 70F, 80F and 100F SSL VPN support

Unlike 40F/60F, these families keep SSL VPN through 7.6.2. From 7.6.3, only Web mode remains, including the variants in the 8.0 CLI model table. Fortinet confirms the pre-7.6.3 F-series scope.

FortiGate 30G and 50G SSL VPN support

FortiGate 30G/31G and 50G/51G never supported SSL VPN, according to Fortinet’s model-specific Technical Tip. There is no earlier SSL VPN release to retain. Use IPsec remote access.

Documentation discrepancy: the generic 7.4.12 SSL settings CLI list includes 30G/31G. This table follows the explicit model-specific “never supported” guidance, reinforced by their exclusion from the 8.0 web-mode command. The generic command listing does not establish supported SSL VPN operation.

FortiGate 70G SSL VPN support

70G/71G retains SSL VPN on applicable 7.2.x builds; the 90G cutoff does not apply. Its current guidance identifies 7.4.8 as the removal boundary; 7.4.8 release notes remove both modes.

No final 7.2 removal patch is documented. Check your model build; do not assume a 7.4.7 image exists. Web mode is also unavailable in 8.0.

FortiGate 90G SSL VPN support

90G/91G supports SSL VPN in 7.2.11 and 7.4.7. 7.2.12 and 7.4.8 respectively remove both SSL VPN and web mode; later releases do not restore them. Issue 1026775 in 7.2.12 and the 7.4.8 notice document the change.

The older branch has its own 7.0.15 → 7.0.16 cutoff. SSL VPN is already absent in 7.6.1; 7.6.2 is not a fallback. 7.0.16 notice; 7.6.1 notice.

FortiGate 120G SSL VPN support

120G/121G is not part of the smaller G-series removal group: SSL VPN works through 7.6.2, then 7.6.3 leaves web mode only. Model-specific confirmation; 8.0 web mode availability.

Older E models: a firmware ceiling is not SSL VPN removal

The E-series table shows firmware ceilings, not removal releases. 100E/101E stops at 7.2, even though the smaller 60E/80E/90E families can run 7.4. None of these E models can run 7.6.

No FG-31E appears in the checked model lists. Hardware End of Support and FortiOS software support are separate.

H-series coverage

No FortiGate H-series models in the 30–120 class were present in Fortinet’s supported-model documentation when this matrix was last verified on 6 October 2026. Current supported-model list.

Can I upgrade and keep FortiClient SSL VPN?

  • 40F or 60F on 7.4.x → 7.6: no. Migrate to IPsec before the upgrade; both SSL VPN modes disappear at 7.6.0.
  • 80F on 7.6.2 → 7.6.3: no. Tunnel mode disappears; browser Web mode remains.
  • 90G on 7.4.7 → 7.4.8: no. This patch upgrade removes both SSL VPN modes.
  • 120G on 7.6.2 → 7.6.3: no for FortiClient SSL VPN; yes for the retained browser web-mode feature.
  • 30G on any applicable release: no supported SSL VPN tunnel is available. Use IPsec.
  • 60E on 7.4 → 7.6: this is unsupported firmware for the hardware, not an available upgrade that removes SSL VPN.

FortiOS support status

As of 6 October 2026. Support requires an applicable contract and supported hardware.

BranchEoESEoSLTS / extended supportStatus
7.030 March 202430 September 2025No general LTS verified; explicit exceptions onlyStandard support ended
7.231 March 202530 September 2026LTS: to 31 March 2028 with eligible FortiCare EliteStandard support ended
7.411 May 202711 November 2028No LTS designation or extra period verifiedEngineering support
7.625 July 202825 January 2030LTS; revised Extended EoS needs confirmationEngineering support
8.0Not publicly verifiedNot publicly verifiedNot verifiedCurrent branch; confirm support horizon

Dates: Fortinet’s published 7.0–7.6 lifecycle table and March 2026 extension announcement. The January 2026 guidance supplies 7.2’s Extended EoS, but its older 7.4/7.6 standard dates are superseded. Its 7.6 Extended EoS predates the extension; confirm the revised date with Fortinet. The Product Life Cycle portal required login during verification; no 8.0 dates have been inferred.

“SSL VPN still works” does not necessarily mean “this firmware is still a sensible supported choice.” Keep security maintenance current and plan IPsec migration before the removal boundary.

Hardware-limited last-firmware exceptions may apply while the appliance remains supported. Confirm the appliance and contract with Fortinet. Support policy and exceptions.

What EoES, EoS, LTS and FortiCare Elite mean

EoES — End of Engineering Support
Ordinary defect-fix expectations change under Fortinet’s support policy.
EoS — End of Support
Normal software support for the branch has ended.
LTS — Long Term Support
A longer maintenance designation, not automatic extended entitlement.
Extended EoS / EEoS
An explicitly offered support period beyond standard EoS.
FortiCare Elite
Required for LTS updates after standard EoS; Essential and Premium do not qualify.

Fortinet’s entitlement conditions. Hardware EoS applies to the appliance, not the FortiOS branch.

GUI hidden versus feature removed

FortiOS 7.4.1 hides SSL VPN menus by default; existing enabled configurations can retain visibility. Hidden does not mean removed. On supported models/releases, reveal the menu with:

Supported SSL VPN models/releases only — GUI visibility
config system settings
    set gui-sslvpn enable
end

7.4 web mode is separately disabled/hidden: set sslvpn-web-mode enable under config system global enables it when needed. Neither control restores a removed feature. Fortinet’s exact defaults and controls.

How to check your FortiGate

Check model, version and build
get system status
Check whether SSL VPN / web-mode configuration exists
show vpn ssl settings
Check RAM for the 2 GB restriction
diagnose hardware sysinfo conserve

Run the settings check as super_admin in the relevant VDOM. A parse error may mean the feature is unavailable; check permissions and context first. In 7.6.3+, a successful command means web-mode settings only. Configuration check.

For 2 GB restrictions, check total RAM below 2000 MB, not free memory; model-specific exclusions still apply. Special firmware images also need the correct branch point. RAM check · Build check.

Before upgrading a FortiGate that uses SSL VPN

  1. Separate FortiClient users from web-mode users.
  2. Match the exact model, target patch and build to the matrix and hardware list.
  3. Migrate and test users on dial-up IPsec before the cutoff.
  4. Follow Fortinet’s supported upgrade path.
  5. Back up the configuration and test the rollback plan.

Fortinet explicitly states that settings are not upgraded across the 7.6.0 affected-model removal, 7.4.8 G-series removal and 7.6.3 tunnel-mode removal. Do not assume a downgrade reconstructs discarded configuration. The 7.6.3 notice links Fortinet’s migration procedures.

If the replacement IPsec tunnel connects but cannot pass traffic, see FortiGate hardware offload problems and IPsec routes, policies and selectors. For packet-size problems, use the IPsec overhead calculator.

Frequently asked questions

What is the last FortiOS version with FortiClient SSL VPN?

7.6.2 on eligible models in the 7.6 branch; older branches may retain SSL VPN. 40F/60F stop at 7.4.x, while 90G stops at 7.2.11 or 7.4.7.

Does FortiOS 7.6 support SSL VPN?

Eligible models retain it through 7.6.2. 40F/60F lose it at 7.6.0; 90G already lacks it in 7.6.1.

Does FortiOS 7.6.3 support SSL VPN?

No FortiGate supports FortiClient SSL VPN in 7.6.3 or later. Some models retain web mode.

Which FortiGate models lose SSL VPN in FortiOS 7.6?

40F/60F/61F lose both modes at 7.6.0; 90G/91G lack both in 7.6.1. All remaining SSL VPN models lose it at 7.6.3.

Does FortiGate 40F support SSL VPN?

Yes on applicable 7.4.x and earlier releases. No from 7.6.0; Web mode is also unavailable.

Does FortiGate 60F support SSL VPN?

Yes on applicable 7.4.x and earlier releases, including 61F. Both SSL VPN and web mode disappear at 7.6.0.

Does FortiGate 70F or 80F support SSL VPN?

Yes through 7.6.2, including 71F/81F and 100F/101F. 7.6.3 leaves web mode only.

Does FortiGate 30G or 50G support SSL VPN?

No. 30G/31G and 50G/51G never supported it from launch.

Does FortiGate 70G support SSL VPN?

Yes on applicable 7.2.x builds. Both modes are absent from 7.4.8; the 90G 7.2.12 cutoff does not apply.

Does FortiGate 90G support SSL VPN? What is its last version?

Yes through 7.2.11 or 7.4.7; 7.2.12 and 7.4.8 respectively remove both modes, including on 91G. The older branch cutoff is 7.0.15 → 7.0.16.

Does FortiGate 120G support SSL VPN?

120G/121G retains SSL VPN through 7.6.2. 7.6.3 leaves web mode only.

What replaced SSL VPN in FortiOS 7.6.3? Is Agentless VPN the same?

Dial-up IPsec replaces FortiClient tunnel access. Agentless VPN is Fortinet’s newer name for web mode, not a FortiClient tunnel.

Why did SSL VPN disappear from the FortiGate GUI?

7.4.1 changed default visibility. On supported models/releases, gui-sslvpn can reveal the menu; it cannot restore a removed feature.

Can I keep SSL VPN by remaining on FortiOS 7.4?

Eligible E/F models and 120G retain it. 90G loses it at 7.4.8; 70G lacks it from 7.4.8, and 30G/50G never supported it. Keep security maintenance current while planning migration.

Is FortiOS 7.2 still supported?

Standard support ended on 30 September 2026. Eligible FortiCare Elite LTS coverage extends to 31 March 2028; hardware-limited last-firmware exceptions are separate.

What is FortiOS EoES versus EoS?

EoES changes engineering and defect-fix support; EoS ends normal software support. LTS extensions require the designated branch and applicable entitlement.

References