When creating a new SSL VPN portal (on Forti OS version 4 MR 2 Patch 9 at least) you may encounter the following message when attempting to save the Portal “The string contains XSS vulnerability characters.”
If this is the case make sure there are no Characters such as ‘ in the portal message. This can be checked in settings.
Life saver! It turns out I was using brackets in the name field.
This worked on a Fortigate 3240C fine.
Thanks again!