Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
alexpendello
New Contributor

Curious about Web Portal for SSLVPN

Is it possible to disable the web portal login for SSLVPN if SSLVPN is configured on a Fortigate firewall, as I manage some devices for which this would be desirable.  For various reasons, for the Fortigates in question, it is not practical to limit the hosts that are allowed to connect to SSLVPN to specific addresses / subnets.  I have deleted content on the login pages through  System -> Replacement Messages to lockdown these devices somewhat.  Was just wondering if there is any way to overall disable this page from appearing on the firewall when accessing through web browser using https://<ip address of fortigate>:<port of SSLVPN> .  It is my understanding that Forticlient access to this configured port, as well as web portal access, both are enabled together, and one cannot be disabled without disabling the other.  Is that correct?

 

Also, if I needed to whitelist a specific subnet for inbound traffic for port 541 for Fortiguard, would it be a subnet associated with Fortinet, and if so, which subnet or FQDN?  Would this be possible?

 

Thank you for your time.

3 REPLIES 3
AEK
SuperUser
SuperUser

Hello

To disallow web access I just disable web mode in all used portal mappings. As you said I also don't think there is a way to disable the page from appearing since the SSL port is shared with tunnel-mode access.

For the second question you may use "Internet Service > Fortinet-*" as source or destination in your firewall rule.

AEK
AEK
Rajneesh
Staff
Staff

Hello @alexpendello ,

You can disable the SSL VPN web-mode globally, and it will prevent the SSL page to load.

Sharing the KB article : https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-disable-SSL-VPN-web-mode-globally/t...

 

 

AEK

Oh so this is a new feature on 7.4.2. Thanks for the information, Rajneesh.

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors