ORIGINAL: knutWhat Selective means is that you want to set up a VIP on one of your external interfaces as a port forward such as: External IP Address: AFree.IP.On.YourWan Mapped IP address: YourMain.Int.Ip.Addr Enable port forwarding External Service Port: 443 Map to Port: the port that SSLVPN is bound to (default is 10443) Click OK Then create a firewall policy from your external int/zone back to your external int/zone Source Int/Zone: External Source Address: the internet Destination Int/Zone: External Destination Address: The Port Forward You Created Above Sched: your schedule here Service: HTTPS Action: Duh :) ok, accept And thats it. You should now be able to go to https://AFree.IP.On.YourWan and have it forward back to your SSLVPN daemon. BTW, Selective, great idea. I hadn' t thought to do it this way. We run our SSLVPN on a high port anyway, but what an easy way (if you had to) to change it. --CheersORIGINAL: Selective one more thing, you dont need to change the port 10443, leave it alone, and do a VIP instead, WAN1 on port 443 -> WAN1 on port 10443 (and of course choose another IP than the interface IP)What do you mean with choosing another IP than the Interface IP? Can' t I make a VIP from 443 to 10443 and use the wan IP?
PCNSE
NSE
StrongSwan
ORIGINAL: soma043 Can' t I change the default 10443 port to 80? For whatever reason, when I change the setting, I get no response when I try to connect. There must be a way to SSL VPN to the box without having to specify the port in the URL?I second to please expand on this. I have all my FortiGate SSLVPN ports on 443, and I moved admin access to another port. Many of my users need to use SSLVPN at places where many ports many be blocked (hotels, airports, China) so having https:// occurring on the industry standard port maximizes compatibility. I get the odd log entry from port scanners hitting the port but I don' t get any actual attempts to access the system by having it on 443t. I get emailed immediately on failed logon attempts and I' ve received exactly zero emails in ~2 years that weren' t from known users.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1113 | |
759 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.