Skip to main content
veechee
New Member
October 18, 2010
Question

SSL VPN Port

  • October 18, 2010
  • 4 replies
  • 13402 views
I' m rolling out SSL VPN at several sites, and I want to balance security adequately against accessibility. Since some public hotspots (e.g., coffee shops, public buildings, hotels) are very restrictive about what ports can be accessed, so my thought is that it might be better to have the SSL VPN on port 443. - Is the default port for the FortiGate SSL VPN (10443/tcp) specific to FortiGate, or is it used by a lot of Firewall/UTM vendors? - Are most of you using port 10443 or do you change that to 443 or another " standard" port that is likely to be let through everywhere? - Any drawbacks to putting the SSL VPN on port 443 instead of the admin interface (I' d prefer to move that off 443 no matter what)?

    4 replies

    emnoc
    New Member
    October 19, 2010
    I don' t know of any fw vendor using 10443. A lot just change the url position for admin and sslvpn. I.e cisco does takes this approach with https://x.x.x.x/admin and it' s sorry asdm approach ;) As far as hotspots, I never found one that block outbound traffic to port 10443, but a lot of client/business location that I' ve been at , have not been to friendly with tight fwpolicy and the allowance of 10443/tcp You can play it safe and swamp the two and if you don' t have https access allowance to the outside interface, you won' t be missing anything.
    veechee
    veecheeAuthor
    New Member
    October 19, 2010
    Thanks for your thoughts. Based on that, I am going to change to port 443 then before I roll out SSL VPN out of my main office. I know my own firewall policies wouldn' t allow 10443 normally for hotspot/guest access. It really got me thinking when I saw the city I' m in roll out WiFi access in all city buildings, and they stated they only allow port 80 and 443 in the notice.
    veechee
    veecheeAuthor
    New Member
    October 19, 2010
    A further question: I have one FortiGate deployed where I forward port 443 now for other SSL services (e.g., OWA). I don' t use SSL VPN that unit right now. If I wanted to use SSL VPN in the future, would I need to move the other services to a different hostname/IP, or could is it possible to terminate an SSL VPN to a VIP?
    ede_pfau
    SuperUser
    SuperUser
    October 19, 2010
    Hi, regarding OWA I' d think that moving OWA to a VIP would be most straightforward. I have not tested moving the SSL VPN service of a FG to a VIP but see no obvious reason why this shouldn' t work either. You will need a " wan" to " wan" policy to implement this. Nice train of thought about using port 443 for SSL VPN.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!