What Is FortiClient? Fortinet's VPN and Endpoint Agent
FortiClient is Fortinet's endpoint agent, most commonly used as the VPN client that connects a user's device to a FortiGate firewall. It can build both SSL VPN and IPsec (IKEv2) tunnels to the corporate network, and in its fuller, centrally-managed form it also provides endpoint security and zero-trust features. If your organisation runs FortiGate firewalls, FortiClient is very likely the VPN software on staff laptops.
Because it is so widely deployed — and because Fortinet's remote-access stack has featured in several notable security stories — it is worth knowing exactly what FortiClient is and how to run it sensibly.
What FortiClient does
At its core FortiClient is a remote-access VPN client for FortiGate gateways. It authenticates the user, negotiates an encrypted tunnel, and routes corporate traffic through the firewall. A free VPN-only build has historically been available for basic connectivity, while the full product — managed through Fortinet's EMS (Endpoint Management Server) — adds antivirus, web filtering, vulnerability scanning and ZTNA agent capabilities.
So 'FortiClient' can mean two things: the lightweight VPN client an individual downloads, or the managed endpoint agent an enterprise deploys as part of the Fortinet Security Fabric. The VPN function is the same; the management and extra security features are what differ.
SSL VPN vs IPsec in FortiClient
FortiClient supports both remote-access modes a FortiGate offers. SSL VPN runs over TLS on port 443 and traverses restrictive networks easily; IPsec (IKEv2) provides an always-on style tunnel. The choice mirrors the general IPsec vs SSL VPN decision, and both are configured on the FortiGate side.
One notable industry shift: Fortinet has been steering customers away from SSL VPN toward IPsec and ZTNA, and newer FortiOS releases have removed SSL-VPN tunnel mode on lower-memory FortiGate models. If you are planning a FortiGate remote-access design in 2026, it is worth checking your model and FortiOS version rather than assuming SSL VPN will always be available.
The security context IT should know
Fortinet's SSL-VPN interface has been the subject of several serious, actively-exploited vulnerabilities in recent years — the kind that let attackers bypass authentication or read files from the device. This is not unique to Fortinet; internet-facing VPN gateways from many vendors have been heavily targeted, because they are exactly where attackers want a foothold.
The practical lessons are the ones we repeat throughout these briefs: patch VPN gateways and clients promptly, expose as little of the management interface as possible, enforce multi-factor authentication, and consider moving remote application access to zero trust to shrink the blast radius. A VPN client is only as safe as the gateway behind it and the patch cadence around both.
Is FortiClient right for you?
How FortiClient is deployed
In practice, FortiClient is configured against a FortiGate that has been set up to accept remote access. For SSL VPN, an administrator enables the SSL-VPN portal on the FortiGate, ties it to a user group and an address range, and users point FortiClient at the gateway's address and port; for IPsec, the FortiGate publishes an IKEv2 dial-up configuration that the client matches. Authentication should be bound to the directory with multi-factor enabled, exactly as for any remote-access VPN.
At scale, organisations deploy and manage FortiClient centrally through Fortinet's EMS rather than having users install it by hand. EMS pushes the configuration, collects endpoint telemetry, and enforces posture and ZTNA rules. The lightweight, free VPN-only build that individuals sometimes download is the same VPN engine without that central management and the extra security modules.
The SSL-VPN shift you should plan for
If your remote access relies on FortiGate SSL VPN, plan around Fortinet's clear direction of travel away from it. Recent FortiOS releases have removed SSL-VPN tunnel mode on lower-memory FortiGate models and Fortinet has been steering customers toward IPsec and ZTNA, partly in response to the string of SSL-VPN vulnerabilities across the industry. Check your specific model's memory and your FortiOS version against Fortinet's current documentation rather than assuming SSL-VPN tunnel mode will remain available.
The safe reading is that IPsec (IKEv2) and ZTNA are the strategic remote-access paths on the platform, and SSL VPN is a legacy mode being wound down on smaller hardware. That aligns with the broader move to zero trust and is worth factoring into any FortiGate remote-access design you build in 2026.
The bottom line
FortiClient is a capable, widely-deployed endpoint and VPN client, and if your organisation runs FortiGate it is the sensible default because everything integrates. The nuance is that its best-known mode — SSL VPN — is the one Fortinet is steadily de-emphasising, and the one that has drawn the most attacker attention across the industry. Treat that as a planning signal, not a reason to panic: keep it patched, front it with strong authentication, and map a path toward IPsec or ZTNA on the platform.
If you are not already a Fortinet shop, there is no special reason to standardise on FortiClient; you would choose it because you chose FortiGate, not the other way round. Either way, the durable lessons outlast any one product — authenticate strongly, expose as little as possible, patch the gateway relentlessly, and keep narrowing broad network access toward per-application access where it fits your environment.
FortiClient makes obvious sense if you already run FortiGate firewalls, since it is the native client and integrates with the rest of the Fortinet fabric. If you do not, there is no reason to adopt it specifically — the VPN protocols compared for IT brief covers the vendor-neutral options, and the business VPN guide frames the wider decision of what kind of remote access to run at all.
Frequently asked questions
What is FortiClient used for?
Is FortiClient free?
Does FortiClient use SSL VPN or IPsec?
Is FortiClient safe to use?
Is Fortinet phasing out SSL VPN?
Start with the business VPN guide, or read how IPsec VPNs work in detail.