Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
taglerock
New Contributor

Disable Management Access on WAN Interface

We have a Fortigate 50E that we are trying to disable management access via the external interface on.  I have followed the instructions here:

 

https://docs.fortinet.com/document/fortigate/6.2.0/hardening-your-fortigate/582009/system-administra...

 

But I haven't had any success

 

To be clear the steps I have done so far are:

1.   Go to Network>Interfaces>Edit WAN1 uncheck HTTPS

 

2. via cli entered the following

config system interface

edit wan1

unset allowaccess

 

Despite doing the steps above when I goto the external IP from outside the network I still get the webui.  Am I missing something?

 

8 REPLIES 8
andrewbailey
Contributor II

Hi taglerock,

 

What you are doing seems correct. Of course you should disable everything on the external interface really- http will redirect to https by default so http needs to be disabled too, ssh should also be disabled unless you have a good use case for it etc.

 

However, it’s worth noting that the SSL VPN uses port 443 (HTTPS) by default. Is it possible this is the webgui you are hitting?

 

For a default config you should get a warning saying that there is a conflict with between the web admin interface (the webgui you refer to) and the SSL VPN interface as both use port 443. Typically the web admin interface is changed to a different port (eg 4433 or what ever suits your network).

 

The process of changing the default web admin port is described here in the 7.0.3 administration guide:-

 

https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/616955/configuring-ports

 

You didn’t say which software version you were using (and the 50E does not support the 7.X releases) but the process is similar for earlier versions too.

 

This document:-

 

https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/869159/ssl-vpn-best-practice...

 

Describes the best practices for SSL VPNs and towards the bottoms shows how to disable the SSL VPN- that might be worth trying just to see if it resolves your issue.

 

Give that a try and let us know how you get on. Good luck!

 

Kind Regards,

 

 

Andy.

 

 

 

taglerock

I'm pretty sure you are correct and it is the VPN login page.  I checked the link in your post but when I tried following the instructions there was no option on the firewall to disable ssl vpn that i could find.   The firmware version installed on the firewall currently is FortiOS v5.4.4, Build 1117.  I believe this is an older version, if so perhaps the option to disable ssl-vpn is not present in this version?

Toshi_Esumi
Esteemed Contributor III

Which do you want to disable? Web GUI admin login to the 50E or SSL VPN to get on the 50E? They're two different things.

taglerock

The web admin ui is disabled.  I was mistakenly thinking the page i was getting when accessing the external ip from outside the network was the web ui admin login page because they look similar.  However there is no need for either page to be accessible from the outside so I would like to turn off the SSL VPN login page as well.

Toshi_Esumi
Esteemed Contributor III

At the SSL-VPN Settings GUI, remove the portal you have configured at the bottom, then remove all interfaces at "Listen on interface(s)" section at the top. That should disable SSL VPN.

Toshi_Esumi
Esteemed Contributor III

Since you have 5.4 the order in the GUI might be different. But you should be able to find those config items.

But if you want to "hardening" the FW, the first thing you should consider is to upgrade it to more modern version at least 6.0.x. 6.2.x is the last major version that supports 50E, which you probably know already.

Toshi_Esumi
Esteemed Contributor III

If you do "unset allowaccess" on the interface, nobody can get in via the interface. Does the IP to get in happen to be on a different interface, like a VLAN subinterface on wan1?

 

Toshi

tomhanks88
New Contributor

The process of changing the default web admin port is described here in the 7.0.3 administration guide:-

 

https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/616955/configuring-ports

 

You didn’t say which software version you were using (and the 50E does not support the 7.X releases) but the process is similar for earlier versions too.

 

This document:-

 

https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/869159/ssl-vpn-best-practice... happy wheels unblocked

 

Describes the best practices for SSL VPNs and towards the bottoms shows how to disable the SSL VPN- that might be worth trying just to see if it resolves your issue.

 

Give that a try and let us know how you get on. Good luck!

 

THanks for  your link. helpful.

Labels
Top Kudoed Authors