Skip to main content
taglerock
New Member
January 10, 2022
Question

Disable Management Access on WAN Interface

  • January 10, 2022
  • 8 replies
  • 28168 views

We have a Fortigate 50E that we are trying to disable management access via the external interface on.  I have followed the instructions here:

 

https://docs.fortinet.com/document/fortigate/6.2.0/hardening-your-fortigate/582009/system-administrator-best-practices

 

But I haven't had any success

 

To be clear the steps I have done so far are:

1.   Go to Network>Interfaces>Edit WAN1 uncheck HTTPS

 

2. via cli entered the following

config system interface

edit wan1

unset allowaccess

 

Despite doing the steps above when I goto the external IP from outside the network I still get the webui.  Am I missing something?

 

8 replies

andrewbailey
New Member
January 10, 2022

Hi taglerock,

 

What you are doing seems correct. Of course you should disable everything on the external interface really- http will redirect to https by default so http needs to be disabled too, ssh should also be disabled unless you have a good use case for it etc.

 

However, it’s worth noting that the SSL VPN uses port 443 (HTTPS) by default. Is it possible this is the webgui you are hitting?

 

For a default config you should get a warning saying that there is a conflict with between the web admin interface (the webgui you refer to) and the SSL VPN interface as both use port 443. Typically the web admin interface is changed to a different port (eg 4433 or what ever suits your network).

 

The process of changing the default web admin port is described here in the 7.0.3 administration guide:-

 

https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/616955/configuring-ports

 

You didn’t say which software version you were using (and the 50E does not support the 7.X releases) but the process is similar for earlier versions too.

 

This document:-

 

https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/869159/ssl-vpn-best-practices

 

Describes the best practices for SSL VPNs and towards the bottoms shows how to disable the SSL VPN- that might be worth trying just to see if it resolves your issue.

 

Give that a try and let us know how you get on. Good luck!

 

Kind Regards,

 

 

Andy.

 

 

 

taglerock
taglerockAuthor
New Member
January 10, 2022

I'm pretty sure you are correct and it is the VPN login page.  I checked the link in your post but when I tried following the instructions there was no option on the firewall to disable ssl vpn that i could find.   The firmware version installed on the firewall currently is FortiOS v5.4.4, Build 1117.  I believe this is an older version, if so perhaps the option to disable ssl-vpn is not present in this version?

Toshi_Esumi
SuperUser
SuperUser
January 10, 2022

Which do you want to disable? Web GUI admin login to the 50E or SSL VPN to get on the 50E? They're two different things.

Toshi_Esumi
SuperUser
SuperUser
January 10, 2022

If you do "unset allowaccess" on the interface, nobody can get in via the interface. Does the IP to get in happen to be on a different interface, like a VLAN subinterface on wan1?

 

Toshi

tomhanks88
New Member
January 12, 2022

The process of changing the default web admin port is described here in the 7.0.3 administration guide:-

 

https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/616955/configuring-ports

 

You didn’t say which software version you were using (and the 50E does not support the 7.X releases) but the process is similar for earlier versions too.

 

This document:-

 

https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/869159/ssl-vpn-best-practice... happy wheels unblocked

 

Describes the best practices for SSL VPNs and towards the bottoms shows how to disable the SSL VPN- that might be worth trying just to see if it resolves your issue.

 

Give that a try and let us know how you get on. Good luck!

 

THanks for  your link. helpful.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!