Skip to main content
Ron_Uss
New Member
February 17, 2015
Solved

Disable SSLVPN webportal page

  • February 17, 2015
  • 16 replies
  • 96399 views

Hello

After pentests we have issue about showing SSLVPN webpage. I need use SSLVPN only in tunnel mode (this is not problem), but without showing any page in browser. I looked on cli and gui and can`t still found any solution, how disable web page, but still have actvite tunnel mode.

Do you have any idea?

Thank you

Best answer by Pacolo

Hey guys,

 

I searched info about disabling SSL-VPN and found this.

 

What I have done is unsetting the options configured through CLI, for example:

 

config vpn ssl settings unset port unset source-interface "wan1"

Regards!

16 replies

vjoshi_FTNT
Staff
Staff
February 17, 2015

Hello,

 

I am positive that there is no such option to disable the access to the Web GUI(ssl-vpn) alone.

However, you can remove all the widgets removed from the portal, again, I don't think this will solve your problem.

 

You can try the below:

 

config vpn ssl settings

set url-obscuration enable

end

 

This field is available when sslvpn-enable(under same vpn ssl settings) is set to enable. Enable to encrypt the host name of the url in the display (web address) of the browser for web mode only. This is a requirement for ICSA ssl vpn certification. Also, if enabled, bookmark details are not visible (field is blank.).

Cheers!

bertimestwo
New Member
September 17, 2018

You can disable "Web Mode" in SSL-VPN Portals.

randomcatperson
Explorer
May 9, 2019

I found that even disabling web-mode on all portals still presented a login page on the outside interface.

I left all portals with everything disabled that I could and then in order for this to go away - I had to delete the SSL security policy in policy & objects > IPv4 policy that permitted it and it no longer works.

This is as close as I could find to disabling SSL.

I'm running 6.0.4

Matt2019
New Member
December 27, 2019

Hi Ron_Uss,

  Have you found a solution to this? I would also like to disable the login page and just use tunnel mode.

 

matt

Che
New Member
January 2, 2020

On the SSL-VPN Settings page, you can remove the WAN interfaces from the "Listen On Interface(s)" config. The firewall requires at least one interface in this field but you can add DMZ or some other unused interface to prevent it from responding on the internet.

 

Update:  This disables the SSL VPN completely which is what I do when using the IPSec based Forticlient VPN config instead.

leo1
New Member
February 26, 2021

There is no option to disable Web GUI access for SSL VPN 

But you can edit the replacement Message for SSL-VPN login page. 

SYSTEM> Replacement Message > SSL-VPN login page.

 

You can Deleted the Body of HTML. then when you try to access your web portal(SSL-VPN) the login page will not show.

pjang
Staff & Editor
Staff & Editor
March 13, 2025

Piggybacking on what @cyberadius suggested above, we have the following Community KB articles that cover similar info (I'll leave them here for future reference):

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.