The article explains the SSL-VPN Tunnel mode will go through the Proxy PAC file setting.
Explanation
If there is a proxy PAC file configured in the user window environment, when connecting SSL-VPN tunnel via FortiClient, the tunnel mode connection will dynamically load the ‘WinHttp.dll’ to support proxy.pac file.
Bypass SSL-VPN destination address in the proxy.pac file, if this setting is not required.