Created on
01-29-2025
08:00 AM
Edited on
01-30-2025
06:36 AM
By
Jean-Philippe_P
Description | This article describes how to manually adjust the sys_reco threshold settings to modify the custom port for SSL VPN traffic. |
Scope | FortiDDoS-F. |
Solution |
Topology:
Remote SSL VPN user (custom port 20443) ---> ISP link ----> FortiDDoS -----> FortiGate ---> (Internal network).
Monitor -> Layer 3/4/7 (Traffic Monitor) -> select (SPP and Layer 4, examine the UDP graphic). If some drops are present, set a large threshold for Layer 4/ UDP Ports.
If FortiGate uses dtls on the connection, disable it on the FortiDDoS DLTS and SSL Profile:
To verify whether it is enabled on FortiClient:
To verify whether it is enabled on FortiGate through the CLI:
config vpn ssl setting
Validate traffic Monitor -> Layer 3/4/7 -> to see if there is any other drop and if an increase is required in the threshold on the custom port. Optionally, use Wireshark on the Remote user's PC when replicating the SSL VPN connection to confirm the traffic/ports in use. |