Why is vpnprovider using so much data on my Mac?
Last updated: 2026-08-05
vpnprovider is Fortinet’s packet-tunnel network extension for FortiClient SSL VPN, not an Apple system process. Its traffic may include data from every app routed through the VPN, so a high total does not by itself indicate a secret upload.
What it is
vpnprovider is a third-party macOS Network Extension installed by Fortinet FortiClient. It is not a built-in Apple process. The verified extension uses the bundle identifier com.fortinet.forticlient.macos.vpn.nwextension, and the inspected installed copy was signed by Fortinet team AH4XFXJ7DK.
The extension declares itself as a packet-tunnel provider. macOS gives a packet-tunnel provider the network packets that match the active VPN routing rules, and the provider handles them through a virtual VPN interface. In this case, vpnprovider participates in FortiClient SSL VPN tunnel transport.
Fortinet identifies the same executable as its SSL VPN Service. That scope matters: vpnprovider should not be treated as a collective name for every FortiClient networking feature. FortiClient’s web filtering, proxy filtering, packet filtering, and IPsec services use other components.
You may also encounter names such as FortiClient VPN, FortiClient SSL VPN, FortiClient VPN Tunnel, FortiTray, nwextension, or com.fortinet.fo. The last of those is not a second complete bundle identifier. It can be a truncated process name shown by nettop; the verified full identifier is com.fortinet.forticlient.macos.vpn.nwextension.
Why it talks to the network
macOS can start vpnprovider after you connect from FortiClient or FortiTray. It may also start when an organization’s on-demand or automatic connection policy is triggered, so seeing it active does not always mean someone manually pressed a Connect button.
The extension’s outer tunnel connection normally goes to an SSL VPN gateway configured by the user or an administrator, such as a FortiGate or FortiSASE gateway. FortiClient uses a configurable TCP port. TCP 443 is common in Fortinet configurations, while UDP or DTLS may also be used.
Traffic inside that tunnel can have several sources. It may carry requests to internal organizational services, VPN-routed DNS queries, or ordinary internet traffic when a full tunnel is configured. Split-tunnel routing may send only selected destinations through vpnprovider, while per-app VPN rules may limit the tunnel to particular applications. The process name alone therefore cannot tell you whether the entire Mac, one application, or only a set of routes is using the tunnel.
How much traffic is normal
There is no reliable universal baseline for vpnprovider, and a fixed MB or GB figure would be misleading. When the VPN is disconnected, traffic can be close to zero apart from small amounts of startup or status activity. Once connected, it may range from intermittent handshake and keepalive traffic to the same order of magnitude as every application workload routed through the VPN. File transfers and audio or video streams can therefore make its total rise quickly.
The displayed number also depends on the accounting tool. Apple and Fortinet do not provide a uniform guarantee about whether bytes are assigned to the originating application, the tunnel extension, or both. They likewise do not guarantee consistent treatment of encryption overhead, retransmissions, or possible secondary counting across tools.
For that reason, a large cumulative total is not enough to decide that vpnprovider itself downloaded or uploaded the reported amount as application content. The useful comparison is between its activity, the VPN connection period, and the applications or routes that were using the tunnel at that time.
Can you turn it off
You can disconnect vpnprovider when you do not need the FortiClient VPN, but the consequence is loss of the network paths supplied by that tunnel. Open System Settings, go to VPN, select FortiClient VPN Tunnel or the administrator-defined service name, and turn it off.
To disable the extension itself on macOS Sequoia, go to System Settings > General > Login Items & Extensions > Network Extensions > FortiTray and turn it off. On macOS Tahoe, the path is System Settings > General > Login Items & Extensions > By Category > Network Extensions > FortiTray. Some older installations may show vpnprovider instead. Earlier macOS releases do not provide this Network Extensions panel.
Disconnecting can make internal networks, protected services, and VPN-provided DNS unavailable. Under full-tunnel, per-app VPN, or always-on policies, affected applications may lose network access entirely. Disabling the FortiTray network extension prevents FortiClient SSL VPN from connecting normally and may violate an organization’s device-compliance policy. On an MDM-managed Mac, the switch may be unavailable or the policy may turn the extension back on.
What people get wrong
- “vpnprovider is an Apple process or malware.” The verified extension is a Fortinet component installed with FortiClient and signed by Fortinet team
AH4XFXJ7DK. It is not built into macOS.
- “High vpnprovider traffic proves FortiClient is secretly uploading local data.” That conclusion does not follow from the byte count. A packet-tunnel provider can be credited with traffic from other applications routed through the VPN. Cumulative bytes alone reveal neither the content nor the destination.
- “FortiClient VPN always takes over all Mac traffic.” Apple’s packet-tunnel system supports included routes, excluded routes, and per-app VPN. The actual configuration can be full-tunnel or split-tunnel.
- “Quitting or disabling vpnprovider is a harmless network optimization.” Doing so interrupts the VPN. Organizational resources can become unreachable immediately, and managed applications may lose all connectivity.
- “vpnprovider is FortiClient’s web filter, application firewall, or proxy filter.” Fortinet uses separate web-filter, proxy, and packet-filter extensions for those functions.
- “com.fortinet.fo is another complete bundle ID.” It can be a name truncated by
nettop. The verified full bundle identifier iscom.fortinet.forticlient.macos.vpn.nwextension.
- “vpnprovider contains every FortiClient VPN protocol implementation.” That is too broad. Fortinet identifies this executable as the SSL VPN Service and lists IPsec services under other process names. Internal responsibilities may still change between releases.
- “Already deduped in totals is guaranteed by macOS or FortiClient.” It is not. Deduplication is an implementation choice made by each traffic-statistics product, and neither Apple nor Fortinet guarantees identical cross-tool accounting.
Seeing what it actually used
Next, inspect vpnprovider in Bytetally over the exact period when the VPN was connected, then compare its timeline with the applications and transfers active during that window. Treat the number as tunnel-attributed traffic rather than proof that vpnprovider created every byte. Also check whether the VPN was full-tunnel, split-tunnel, per-app, or automatically activated before drawing a conclusion.
Related processes
Common questions
Is vpnprovider malware?
The verified vpnprovider extension is installed with FortiClient and signed by Fortinet team AH4XFXJ7DK. It is not an Apple system process.
Why is vpnprovider using so much data?
As a packet-tunnel provider, vpnprovider may be credited with traffic generated by other applications and routed through the VPN. The total can also include tunnel control traffic, encryption overhead, and retransmissions.
Can I disable vpnprovider?
Yes, but disconnecting or disabling it interrupts FortiClient SSL VPN. Internal services, VPN DNS, and applications covered by full-tunnel, per-app, or always-on policies may then lose network access.
Does vpnprovider send all Mac traffic through FortiClient?
Not necessarily. The configured VPN may use a full tunnel, split routing, excluded routes, or per-app VPN rules.
See exactly how much it used
Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.
Download Free on the Mac App StoremacOS 14 Sonoma or later · 100% on-device · No account