Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
soma043
New Contributor

SSL VPN on port 80

Can' t I change the default 10443 port to 80? For whatever reason, when I change the setting, I get no response when I try to connect. There must be a way to SSL VPN to the box without having to specify the port in the URL?
14 REPLIES 14
brianmac64

ORIGINAL: knut
ORIGINAL: Selective one more thing, you dont need to change the port 10443, leave it alone, and do a VIP instead, WAN1 on port 443 -> WAN1 on port 10443 (and of course choose another IP than the interface IP)
What do you mean with choosing another IP than the Interface IP? Can' t I make a VIP from 443 to 10443 and use the wan IP?
What Selective means is that you want to set up a VIP on one of your external interfaces as a port forward such as: External IP Address: AFree.IP.On.YourWan Mapped IP address: YourMain.Int.Ip.Addr Enable port forwarding External Service Port: 443 Map to Port: the port that SSLVPN is bound to (default is 10443) Click OK Then create a firewall policy from your external int/zone back to your external int/zone Source Int/Zone: External Source Address: the internet Destination Int/Zone: External Destination Address: The Port Forward You Created Above Sched: your schedule here Service: HTTPS Action: Duh :) ok, accept And thats it. You should now be able to go to https://AFree.IP.On.YourWan and have it forward back to your SSLVPN daemon. BTW, Selective, great idea. I hadn' t thought to do it this way. We run our SSLVPN on a high port anyway, but what an easy way (if you had to) to change it. --Cheers
moo?
moo?
emnoc
Esteemed Contributor III

bingo on the above One more thing to considered, depending on who and what your end-users are sitting on, content filters might flag https like data on port80 and block it. The pros and cons of where to place the SSLVPN function has to be looked at very closely. Fortinet, should really think about a HTTP_redirect to the secured port, that would allow you to managed on 443 ( admin ), run the SSLVPN on whatever port, and when the client connects to http://yoursslvpngw/ he or she is redirect to https://yourserver:newport number. Both cisco and juniper supports this. The next best thing woud be something similar to what fortimail does; https://yourgateway/admin ( for administration ) vrs https://yourgateway/ ( for user mail access ) So based on the URL, you get one or the other. just my 2 cts opinion on the matter.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau
SuperUser
SuperUser

...or just move the HTTPS admin port to something else - I commonly do that just to avoid all the HTTPS attacks. And agreed, remote administration is best on the internal port + a dial-in IPsec VPN.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
veechee
New Contributor

ORIGINAL: soma043 Can' t I change the default 10443 port to 80? For whatever reason, when I change the setting, I get no response when I try to connect. There must be a way to SSL VPN to the box without having to specify the port in the URL?
I second to please expand on this. I have all my FortiGate SSLVPN ports on 443, and I moved admin access to another port. Many of my users need to use SSLVPN at places where many ports many be blocked (hotels, airports, China) so having https:// occurring on the industry standard port maximizes compatibility. I get the odd log entry from port scanners hitting the port but I don' t get any actual attempts to access the system by having it on 443t. I get emailed immediately on failed logon attempts and I' ve received exactly zero emails in ~2 years that weren' t from known users.
TopJimmy
New Contributor

I actually don' t admin the firewalls from outside so moving the admin port to something else besides 443 is no big deal to me. I guess I' ll move forward with that plan.
-TJ
-TJ
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors