Why is vpnprovider using so much data on my Mac?

Last updated: 2026-08-05

vpnprovider is Fortinet’s packet-tunnel network extension for FortiClient SSL VPN, not an Apple system process. Its traffic may include data from every app routed through the VPN, so a high total does not by itself indicate a secret upload.

What it is

vpnprovider is a third-party macOS Network Extension installed by Fortinet FortiClient. It is not a built-in Apple process. The verified extension uses the bundle identifier com.fortinet.forticlient.macos.vpn.nwextension, and the inspected installed copy was signed by Fortinet team AH4XFXJ7DK.

The extension declares itself as a packet-tunnel provider. macOS gives a packet-tunnel provider the network packets that match the active VPN routing rules, and the provider handles them through a virtual VPN interface. In this case, vpnprovider participates in FortiClient SSL VPN tunnel transport.

Fortinet identifies the same executable as its SSL VPN Service. That scope matters: vpnprovider should not be treated as a collective name for every FortiClient networking feature. FortiClient’s web filtering, proxy filtering, packet filtering, and IPsec services use other components.

You may also encounter names such as FortiClient VPN, FortiClient SSL VPN, FortiClient VPN Tunnel, FortiTray, nwextension, or com.fortinet.fo. The last of those is not a second complete bundle identifier. It can be a truncated process name shown by nettop; the verified full identifier is com.fortinet.forticlient.macos.vpn.nwextension.

Why it talks to the network

macOS can start vpnprovider after you connect from FortiClient or FortiTray. It may also start when an organization’s on-demand or automatic connection policy is triggered, so seeing it active does not always mean someone manually pressed a Connect button.

The extension’s outer tunnel connection normally goes to an SSL VPN gateway configured by the user or an administrator, such as a FortiGate or FortiSASE gateway. FortiClient uses a configurable TCP port. TCP 443 is common in Fortinet configurations, while UDP or DTLS may also be used.

Traffic inside that tunnel can have several sources. It may carry requests to internal organizational services, VPN-routed DNS queries, or ordinary internet traffic when a full tunnel is configured. Split-tunnel routing may send only selected destinations through vpnprovider, while per-app VPN rules may limit the tunnel to particular applications. The process name alone therefore cannot tell you whether the entire Mac, one application, or only a set of routes is using the tunnel.

How much traffic is normal

There is no reliable universal baseline for vpnprovider, and a fixed MB or GB figure would be misleading. When the VPN is disconnected, traffic can be close to zero apart from small amounts of startup or status activity. Once connected, it may range from intermittent handshake and keepalive traffic to the same order of magnitude as every application workload routed through the VPN. File transfers and audio or video streams can therefore make its total rise quickly.

The displayed number also depends on the accounting tool. Apple and Fortinet do not provide a uniform guarantee about whether bytes are assigned to the originating application, the tunnel extension, or both. They likewise do not guarantee consistent treatment of encryption overhead, retransmissions, or possible secondary counting across tools.

For that reason, a large cumulative total is not enough to decide that vpnprovider itself downloaded or uploaded the reported amount as application content. The useful comparison is between its activity, the VPN connection period, and the applications or routes that were using the tunnel at that time.

Can you turn it off

You can disconnect vpnprovider when you do not need the FortiClient VPN, but the consequence is loss of the network paths supplied by that tunnel. Open System Settings, go to VPN, select FortiClient VPN Tunnel or the administrator-defined service name, and turn it off.

To disable the extension itself on macOS Sequoia, go to System Settings > General > Login Items & Extensions > Network Extensions > FortiTray and turn it off. On macOS Tahoe, the path is System Settings > General > Login Items & Extensions > By Category > Network Extensions > FortiTray. Some older installations may show vpnprovider instead. Earlier macOS releases do not provide this Network Extensions panel.

Disconnecting can make internal networks, protected services, and VPN-provided DNS unavailable. Under full-tunnel, per-app VPN, or always-on policies, affected applications may lose network access entirely. Disabling the FortiTray network extension prevents FortiClient SSL VPN from connecting normally and may violate an organization’s device-compliance policy. On an MDM-managed Mac, the switch may be unavailable or the policy may turn the extension back on.

What people get wrong

Seeing what it actually used

Next, inspect vpnprovider in Bytetally over the exact period when the VPN was connected, then compare its timeline with the applications and transfers active during that window. Treat the number as tunnel-attributed traffic rather than proof that vpnprovider created every byte. Also check whether the VPN was full-tunnel, split-tunnel, per-app, or automatically activated before drawing a conclusion.

Related processes

Common questions

Is vpnprovider malware?

The verified vpnprovider extension is installed with FortiClient and signed by Fortinet team AH4XFXJ7DK. It is not an Apple system process.

Why is vpnprovider using so much data?

As a packet-tunnel provider, vpnprovider may be credited with traffic generated by other applications and routed through the VPN. The total can also include tunnel control traffic, encryption overhead, and retransmissions.

Can I disable vpnprovider?

Yes, but disconnecting or disabling it interrupts FortiClient SSL VPN. Internal services, VPN DNS, and applications covered by full-tunnel, per-app, or always-on policies may then lose network access.

Does vpnprovider send all Mac traffic through FortiClient?

Not necessarily. The configured VPN may use a full tunnel, split routing, excluded routes, or per-app VPN rules.

See exactly how much it used

Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.

Download Free on the Mac App Store

macOS 14 Sonoma or later · 100% on-device · No account