Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
quad3datwork
New Contributor

Bind SSL VPN to specific IP

Currently we have one static IP that already have port 443 assigned for a purpose. We are looking to get additional IPs assigns to WAN and map SSL VPN to a specific IP... is this possible? I only see Login Port on my 80C. Thanks.
10 REPLIES 10
SteveRoadWarrior
New Contributor III

You can change the port which the SSL VPN uses. So, instead of using https://1.2.3.4 for SSL VPN login, your users will need to use https://1.2.3.4:10443 which happens to be the default. Why not try your browser adjusted to port 10443 (see above) and see if you get a login screen?
SteveRoadWarrior
New Contributor III

You' ll need to review the directions for setting up the SSL VPN. They will be different depending on the version code you' re running.
quad3datwork
New Contributor

SteveRoadWarrior, thanks for chiming in. Unfortunately, our employees on customer site cannot access anything other than the standard web ports. We' ve tried the port you suggested and many other ports (includes ones below 1024). The customer site does not allow any non-standard port access. I believe I went through the entire doc when I setup SSL VPN and did not see any section mentioning IP bindings... I' m on FortiOS 5.x.
rwpatterson
Valued Contributor III

You could map a virtual IP address to the 10443 portal address.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
SteveRoadWarrior
New Contributor III

Could you try the VIP rule above the SSL VPN rule in the policy list? Does that make a difference as to which 443 destination you see?
SteveRoadWarrior
New Contributor III

and that' s why he' s an expert member...
quad3datwork
New Contributor

I got our new static IPs (/29) assignment from TW. It' s from a totally different Class C. Our original IP (/30) is in 97.79.135.x range. New is in 67.78.34.x range. So what I' d like to do is leave our default IP for company VPN and use the new range for misc port forwarding services. I added Secondary IP Address for wan1 device. For some reason it' s not working from outside. Any ideas?
emnoc
Esteemed Contributor III

You don' t have to do that , if the /29 is routed to your firewall, just define ippool and vips within that range. Do you have a diagram of what your describing?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
quad3datwork
New Contributor

Well, I just spent some quality time with TW on phone. All I have to say about TW is *facepalm*. Short version: I got it working. Long version: What TW did wrong... 1) Didn' t reconfigure our cable modem upon new IPs assignment. 2) Didn' t notify me that changes made to cable modem, while on phone with them, requires restart (making entire office losing Internet 11AM in morning). I guess I should' ve expected this. 3) Didn' t tell me that different Class C cannot co-exist due to policies so my original IP was taken away. Panicking and scramble to quickly reconfigure 80C w/ new IP range. Thanks all.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors