You create a Virtual IP that NATs TCP 443 (or your preferred port) to
the loopback interface. Create a firewall policy from WAN to the
loopback interface, and set your preferred rules on it. Then you switch
the interface in the SSL-VPN Settings, and ...