WAN1 port has got 5 different IPs from the same block. I noticed SSL-VPN is active all of those IPs, but I wish for it to only reply to the main address.
Are you forced to write a specific firewall policy, or is there a way to only bind SSL-VPN service to a single, specific IP address?
Hi,
Is the public IP directly configured on the FGT interface or is there any upstream device
Hi @raffas ,
1) Create one loopback interface with one non-used IP and bind SSL VPN to this interface instead of WAN1;
2) Create one VIP with the Public IP that you need for SSL VPN and map to this loopback IP. It's better to turn on port forwarding with the SSL VPN port number, i.e.: 10443
3) Create a firewall policy with VIP applied from WAN1 to this loopback Interface.
The rest are the regular SSL VPN configurations.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.