Skip to main content
paradoxum
New Member
February 12, 2015
Question

SSL-VPN and HTTPS admin gui on same interface

  • February 12, 2015
  • 3 replies
  • 8757 views

Hi,

I have a 300C with an interface facing my ISP.  On that interface I have several public IPs.  I have remote admin access and SSL VPN enabled.  I would like to access both the SSL VPN and admin GUI from the outside - currently the VPN portal responds when I hit any of the external IPs.  Is there a way to do this on a single interface?  As mentioned I have several IPs to play with.  Is it possible to enable admin access on one of the IPs and SSL VPN on another even though they are bound to the same physical interface?

 

Thanks!

    3 replies

    ede_pfau
    SuperUser
    SuperUser
    February 12, 2015

    Hi,

     

    and welcome to the forums.

    The scenario you are facing is quite a common one. Admin access listens to all addresses on a port, in your case the external WAN port, and the primary and secondary addresses of it. You can solve this by changing the admin HTTPS port, for example to 30443.

     

    Isn't the default port for SSL-VPN set to 10443, for a reason?

    soonguan
    New Member
    February 13, 2015

    Hi, ede is right, even you have plenty of usable fixed public IP. You can only used the IP which configure on the wan interface.

    From the ssl vpn setting, you only can specified, which port you want the fortigate listen to ssl vpn.

     

    The only way is change the port so it wont conflict with other admin ports. EG:if you used 443 on ssl vpn, you got to used others for https admin gui.

    paradoxum
    paradoxumAuthor
    New Member
    March 23, 2015

    Thanks for the info. I changed the admin and ssl-vpn ports and everything is working as it should.  

     

    BTW, the default ssl-vpn port is 443, I understand why, but if it was any other value this wouldn't be an issue.