Skip to main content
nmarx
Staff
Staff
November 26, 2014

Technical Note: Using Port 443 for Administrative Access and SSL VPN

  • November 26, 2014
  • 0 replies
  • 9043 views
Description
Requirements:

· Two publicly routable IP addresses (One additional to the one assigned on the outside interface)

· Space to create a loopback interface (There is a 128-256 max object limit for interfaces)

· Space to create a Virtual IP (maximum VIP objects may be applicable)

· Space to create a firewall address object (max. address objects may be applicable)

· Completed configuration of SSL VPN portal and settings

· Completed configuration of user groups to be used for SSL VPN authentication

Note: A list of max values is available at http://docs.fortinet.com/d/fortigate-fortios-5.2.1-maximum-values-table-1/download

Scope
Accessing the FortiGate's GUI and SSL VPN on TCP port 443.

By default this is not possible as port 443 can only be assigned to one system service.

Since SSL VPN and HTTPS administrative access are two different system services a workaround is required.

Solution
Solution is attached in form of a PDF document.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!