Well. my thoughts: Fortinet and all other vendors are just toooo lazy to patch their SSL products (and why patch it if you can sell something new, like ZTNA)… Why are so many security issues? Because its scanned and pen tested like the hell nowadays like never before… (all started with hearthbleed couple of years ago)… Wait when ipsec vpn is comming more to the attention. On the one hand it uses “SSL”, cause its a good standard. You also do trust websites with HTTPS? right?! right? [insert anakin/padme meme here]
Now to IPSEC. yeah working, but the traffic doesn’t look like anymore like SSL, (event with TCP) which can lead to problems if some starbucks or hotel wifi doesn’t allow ipsec (not just on the ports, just on the type of traffic/protocol). So with SSL mostly the traffic looks like you are accessing some secure webpage which works for almost any other starbucks/hotel internet.
Now to ZTNA… oh my god, i cannot hear that marketing bullshit anymore (throwing things together in some box and mix it together, every vendor in different ways, and then lets sell the cloud boys it with a big whoop). It works for simple stuff (http,https, and mostly known protocols). But if you need access to some specific protocol (like some SAP Connection stuff, cause the SAPGUI legacy is used, AND IT IS USED, or some “you cannot think of time tracking protocol for devices”… that will not work. So ZTNA is NOT a FULL replacement for a VPN. Hence its not a type of access, its a philosophy… (Btw, you can use ztna tags within a dialup connection (ssl/ipsec) if you have an ems). In the end ask yourself which protocol ZTNA itself uses …
Again: Ipsec over TCP… I’m not getting wet here, some extra ports? We’re in 2024/2024… thats like doing some extra protocol shit in 1998…
So imho, currently i would still stick to SSLVPN if you have the hardware (and for sure not use the latest major/minor release… who uses 7.6.0 now ???.. wait at least till patchlevel 5 or 6 or higher xD )
If you have some smaller device where SSLVPN is going be deprecated you should focus on IPSEC VPN Dialup
Sadly It would be nice if they have wireguard support… but well, than they cannot sell the ZTNA Bullshit as Access!
Written with many alcohol 