Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
veechee
New Contributor

SSL VPN Port

I' m rolling out SSL VPN at several sites, and I want to balance security adequately against accessibility. Since some public hotspots (e.g., coffee shops, public buildings, hotels) are very restrictive about what ports can be accessed, so my thought is that it might be better to have the SSL VPN on port 443. - Is the default port for the FortiGate SSL VPN (10443/tcp) specific to FortiGate, or is it used by a lot of Firewall/UTM vendors? - Are most of you using port 10443 or do you change that to 443 or another " standard" port that is likely to be let through everywhere? - Any drawbacks to putting the SSL VPN on port 443 instead of the admin interface (I' d prefer to move that off 443 no matter what)?
4 REPLIES 4
emnoc
Esteemed Contributor III

I don' t know of any fw vendor using 10443. A lot just change the url position for admin and sslvpn. I.e cisco does takes this approach with https://x.x.x.x/admin and it' s sorry asdm approach ;) As far as hotspots, I never found one that block outbound traffic to port 10443, but a lot of client/business location that I' ve been at , have not been to friendly with tight fwpolicy and the allowance of 10443/tcp You can play it safe and swamp the two and if you don' t have https access allowance to the outside interface, you won' t be missing anything.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
veechee
New Contributor

Thanks for your thoughts. Based on that, I am going to change to port 443 then before I roll out SSL VPN out of my main office. I know my own firewall policies wouldn' t allow 10443 normally for hotspot/guest access. It really got me thinking when I saw the city I' m in roll out WiFi access in all city buildings, and they stated they only allow port 80 and 443 in the notice.
veechee
New Contributor

A further question: I have one FortiGate deployed where I forward port 443 now for other SSL services (e.g., OWA). I don' t use SSL VPN that unit right now. If I wanted to use SSL VPN in the future, would I need to move the other services to a different hostname/IP, or could is it possible to terminate an SSL VPN to a VIP?
ede_pfau
SuperUser
SuperUser

Hi, regarding OWA I' d think that moving OWA to a VIP would be most straightforward. I have not tested moving the SSL VPN service of a FG to a VIP but see no obvious reason why this shouldn' t work either. You will need a " wan" to " wan" policy to implement this. Nice train of thought about using port 443 for SSL VPN.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors