Technical Tip: Threshold setting when using a custom port on an SSL VPN connection
| Description | This article describes how to manually adjust the sys_reco threshold settings to modify the custom port for SSL VPN traffic. |
| Scope | FortiDDoS-F. |
| Solution | Topology:
Remote SSL VPN user (custom port 20443) ---> ISP link ----> FortiDDoS -----> FortiGate ---> (Internal network).
Monitor -> Layer 3/4/7 (Traffic Monitor) -> select (SPP and Layer 4, examine the UDP graphic). If some drops are present, set a large threshold for Layer 4/ UDP Ports.
  If FortiGate uses dtls on the connection, disable it on the FortiDDoS DTLS (see DTLS Profile - FortiDDOS handbook) and SSL Profile:
  To verify whether it is enabled on FortiClient:
To verify whether it is enabled on FortiGate through the CLI:
config vpn ssl setting
 
      Validate traffic Monitor -> Layer 3/4/7(Using Traffic Monitor Layer 3/4/7 graphs ) -> to see if there is any other drop, and if an increase is required in the threshold on the custom port. Optionally, use Wireshark on the Remote user's PC when replicating the SSL VPN connection to confirm the traffic/ports in use. |










