Site-to-site VPN tunnels can be established via an SSL connection. SSL VPN connections have distinct roles attached. The tunnel endpoints act as either client or server. The client always initiates the connection, the server responds to client requests. Keep in mind that this contrasts IPsec where both endpoints normally can initiate a connection.

Note – If you run into problems in establishing a connection, check whether SSL scanning is activated with the Web Filter operating in transparent mode. If so, make sure that the target host of the VPN connection has been added to the Transparent Mode Skiplist under Web Protection > Filtering Options > Misc.