Staff
November 26, 2014
Technical Note: Using Port 443 for Administrative Access and SSL VPN
- November 26, 2014
- 0 replies
- 9043 views
Description
Scope
Solution
Requirements:
· Two publicly routable IP addresses (One additional to the one assigned on the outside interface)
· Space to create a loopback interface (There is a 128-256 max object limit for interfaces)
· Space to create a Virtual IP (maximum VIP objects may be applicable)
· Space to create a firewall address object (max. address objects may be applicable)
· Completed configuration of SSL VPN portal and settings
· Completed configuration of user groups to be used for SSL VPN authentication
Note: A list of max values is available at http://docs.fortinet.com/d/fortigate-fortios-5.2.1-maximum-values-table-1/download
· Two publicly routable IP addresses (One additional to the one assigned on the outside interface)
· Space to create a loopback interface (There is a 128-256 max object limit for interfaces)
· Space to create a Virtual IP (maximum VIP objects may be applicable)
· Space to create a firewall address object (max. address objects may be applicable)
· Completed configuration of SSL VPN portal and settings
· Completed configuration of user groups to be used for SSL VPN authentication
Note: A list of max values is available at http://docs.fortinet.com/d/fortigate-fortios-5.2.1-maximum-values-table-1/download
Scope
Accessing the FortiGate's GUI and SSL VPN on TCP port 443.
By default this is not possible as port 443 can only be assigned to one system service.
Since SSL VPN and HTTPS administrative access are two different system services a workaround is required.
By default this is not possible as port 443 can only be assigned to one system service.
Since SSL VPN and HTTPS administrative access are two different system services a workaround is required.
Solution
Solution is attached in form of a PDF document.
