Home / News / RIP FortiClient

03.09.26 Industry News

RIP FortiClient

I recently came across an advertisement on Reddit from one of Fortinet’s competitors, targeting organisations running Fortinet’s FortiClient VPN. I won’t name the vendor here. This isn’t really about them specifically, and if you’re active on r/Fortinet, you’ve probably already seen it.

Healthy competition pushes this market forward, and organisations should regularly question whether their current setup is still the right one for them. That’s not the issue here. The issue is the way the vendor has framed a fairly minor technical improvement in their competitor as an urgent crisis, in order to manufacture a reason to switch vendors. Whether that’s a deliberate tactic or just sloppy research, the effect on the reader is the same, and it’s worth unpacking. Especially as I feel the underlying technical claim doesn’t actually hold up. You win a market by being demonstrably better at what you do, not by making a competitor’s roadmap sound worse than it is.

Before going further, it’s worth being upfront about where we stand. We like the Fortinet stack, but we also rate plenty of the alternative technology out there (including the vendor behind this ad). At Morgan Cyber Solutions, our starting point is always the customer and their requirements. We never focus on our preferences, in fact we make a point of not having any. At the end of the day we’d rather recommend something we can’t sell than push a product that’s a poor fit for our customer.

The claim: “FortiClient VPN is sunsetting”

The ad’s headline was blunt: FortiClient VPN is sunsetting. To most readers, that reads as end-of-life. This is the kind of announcement that implies a major piece of infrastructure needs replacing quickly, before support runs out. That’s exactly the kind of framing that pushes people toward fast, and sometimes poorly considered, decisions.

It isn’t accurate. Here’s what’s actually happening.

What’s actually changing

Fortinet has taken its share of criticism over the past couple of years for vulnerabilities in its SSL-VPN implementation. That’s fair criticism, though it’s worth noting that in most cases those issues were identified by Fortinet’s own teams and patched before public disclosure, which wasn’t always true of other major vendors dealing with VPN vulnerabilities over the same period.

Off the back of that, Fortinet is removing support for SSL-VPN tunnel mode, starting with FortiOS 7.6.3, in favour of IPsec tunnel mode, a protocol widely regarded as the more secure of the two. For anyone still on FortiClient, that means migrating existing tunnels from SSL to IPsec. It does not mean replacing FortiClient itself. Handled properly, this is a fairly minor reconfiguration project, not a rip-and-replace of a licensed, supported VPN solution that’s already embedded in your infrastructure and familiar to your users.

So if you’re running FortiClient, the honest answer is that you don’t need to panic, and you don’t need to replace your VPN. You need to plan a protocol migration.

The claim: “Fortinet’s roadmap ends at ZTNA”

The ad also questions Fortinet Zero Trust Network Access strategy and roadmap, and that ZTNA is where the competition’s advantage begins. That doesn’t hold up either.

It’s worth being precise about what ZTNA actually is, because the term gets stretched by every vendor in this space, Fortinet included. It isn’t a single product; it’s an access model that looks to authenticate the user, then continue to check who they are, what device they’re on, and the posture of that device, before authorising access to a specific resource, rather than granting broad network access at login. That model can run on top of several different underlying tunnel technologies, including SSL, IPsec, or WireGuard.

Fortinet’s ZTNA tagging and posture-check capability works regardless of which protocol sits underneath it; meaning the SSL-to-IPsec migration has no bearing on it. Most importantly, unlike the nameless vendor, within the Fortinet ecosystem, that zero-trust posture checking isn’t limited to remote access; it can be applied to connections within your infrastructure, not just into it. That’s a genuinely useful capability for a lot of businesses, and it’s one the ad doesn’t engage with at all.

What we’d actually recommend

If you’re running FortiClient, there’s no need to overhaul your remote access strategy off the back of this change. If you havnt already just plan the migration from SSL-VPN to IPsec ahead of your FortiOS upgrade, and treat it as routine maintenance/minor project rather than a crisis.

When your VPN solution does come up for renewal, that’s the right moment to properly weigh your options against your business’s actual requirements. We do this kind of impartial comparison with customers regularly, and we’re happy to talk it through if it would help, though that’s a separate conversation from this one.

The bigger question

None of this makes the vendor behind the ad a bad choice for every organisation. For some, it may well be the right one. What it does raise is a broader question worth asking of any vendor pitching you a change: are they winning the argument on the strength of their own product, or by making a competitor’s roadmap sound worse than it actually is?

That’s a fair question to ask of any company you’re about to do business with, including us.

By Thomas Morgan
Share this post

Learn how we can transform your IT and OT environments.

Contact us