Tunneling protocol and encapsulation
SSL VPN uses the TLS protocol for tunneling.
However Fortinet’s IPsec VPN offers the following options for tunneling and encapsulation:
-
Native ESP
-
UDP encapsulation
-
TCP encapsulation with Fortinet proprietary extension to allow inline ASIC offloading
-
TCP encapsulation using RFC 8229
When ESP is used without encapsulation, it connects directly over IP Protocol 50. When ESP is encapsulated within UDP, it uses UDP/500 and UDP/4500 for NAT traversal, which are the options for dial-up IPsec VPN.
In IPsec site-to-site tunnels, the UDP port can be customized. See Configurable IKE port.
In IPsec site-to-site tunnels using IKEv2, the TCP port can also be customized. See Encapsulate ESP packets within TCP headers.