A firewall company's VPN versus a network built on identity. If FortiGate is staying, here's the honest split.
| OpenVLAN | Fortinet SSL VPN / FortiClient | |
|---|---|---|
| Depends on firewall appliances | No | Yes — VPN lives on FortiGate |
| Access model | Identity + device posture per user | Group-based firewall policies |
| Client | Light, silent | FortiClient (EMS-managed) |
| Firewall rule sprawl | None — ACLs in the tailnet | Grows per VPN group |
| Historical CVE exposure | No VPN edge to patch | SSL-VPN has a patch history |
| Licensing | Per user, published | Bundle/quote-based, per-feature |
You need perimeter firewalling, NGFW inspection, and inline DLP as one licensed stack — and already run FortiGates.
The pain is private access: remote workers, multi-site, and cloud resources that shouldn't depend on appliance uptime or capacity.
Keep FortiGate for the perimeter; move user-to-resource access to OpenVLAN. VPN tunnels and their change windows shrink to zero.