We have a Fortigate 50E that we are trying to disable management access via the external interface on. I have followed the instructions here:
But I haven't had any success
To be clear the steps I have done so far are:
1. Go to Network>Interfaces>Edit WAN1 uncheck HTTPS
2. via cli entered the following
config system interface
edit wan1
unset allowaccess
Despite doing the steps above when I goto the external IP from outside the network I still get the webui. Am I missing something?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi taglerock,
What you are doing seems correct. Of course you should disable everything on the external interface really- http will redirect to https by default so http needs to be disabled too, ssh should also be disabled unless you have a good use case for it etc.
However, it’s worth noting that the SSL VPN uses port 443 (HTTPS) by default. Is it possible this is the webgui you are hitting?
For a default config you should get a warning saying that there is a conflict with between the web admin interface (the webgui you refer to) and the SSL VPN interface as both use port 443. Typically the web admin interface is changed to a different port (eg 4433 or what ever suits your network).
The process of changing the default web admin port is described here in the 7.0.3 administration guide:-
https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/616955/configuring-ports
You didn’t say which software version you were using (and the 50E does not support the 7.X releases) but the process is similar for earlier versions too.
This document:-
Describes the best practices for SSL VPNs and towards the bottoms shows how to disable the SSL VPN- that might be worth trying just to see if it resolves your issue.
Give that a try and let us know how you get on. Good luck!
Kind Regards,
Andy.
I'm pretty sure you are correct and it is the VPN login page. I checked the link in your post but when I tried following the instructions there was no option on the firewall to disable ssl vpn that i could find. The firmware version installed on the firewall currently is FortiOS v5.4.4, Build 1117. I believe this is an older version, if so perhaps the option to disable ssl-vpn is not present in this version?
Which do you want to disable? Web GUI admin login to the 50E or SSL VPN to get on the 50E? They're two different things.
The web admin ui is disabled. I was mistakenly thinking the page i was getting when accessing the external ip from outside the network was the web ui admin login page because they look similar. However there is no need for either page to be accessible from the outside so I would like to turn off the SSL VPN login page as well.
At the SSL-VPN Settings GUI, remove the portal you have configured at the bottom, then remove all interfaces at "Listen on interface(s)" section at the top. That should disable SSL VPN.
Created on 01-10-2022 02:55 PM Edited on 01-10-2022 02:55 PM
Since you have 5.4 the order in the GUI might be different. But you should be able to find those config items.
But if you want to "hardening" the FW, the first thing you should consider is to upgrade it to more modern version at least 6.0.x. 6.2.x is the last major version that supports 50E, which you probably know already.
If you do "unset allowaccess" on the interface, nobody can get in via the interface. Does the IP to get in happen to be on a different interface, like a VLAN subinterface on wan1?
Toshi
The process of changing the default web admin port is described here in the 7.0.3 administration guide:-
https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/616955/configuring-ports
You didn’t say which software version you were using (and the 50E does not support the 7.X releases) but the process is similar for earlier versions too.
This document:-
https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/869159/ssl-vpn-best-practice... happy wheels unblocked
Describes the best practices for SSL VPNs and towards the bottoms shows how to disable the SSL VPN- that might be worth trying just to see if it resolves your issue.
Give that a try and let us know how you get on. Good luck!
THanks for your link. helpful.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.