This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SSL VPN Listens on all Interfaces???

Hello Everyone,

Recently with the release of 17.1 I was happy to see the ability to change the SSL VPN port. I decided to take a plunge and move to XG. After a few hours of configuration and getting everything up and running I changed my SSL VPN port to 443 as most of us prefer. I than noticed that no matter the interface/alias IP port 443 is now used on every single interface and I can no longer use a second WAN port/static ip to forward 443 traffic to an internal Web Server or even use Sophos XG WAF on 443. I continue to get the error "Port already in use". I then decided to take a look on the Advanced shell and noticed 2 things. 443 is binded to all interfaces (netstat) and when I look at the openvpn.conf file it also shows that openvpn (SSLVPN) binds to all interfaces on 443. Does anyone here know of a work around or why Sophos dosnt let us choose the port to bind to like they did in UTM?

 

Thanks!

 

EDIT: created feature request as mentioned below: ideas.sophos.com/.../34668685-vpn-ssl-interface



This thread was automatically locked due to age.
Parents
  • Hey Chris,

    I followed up with our team and I would like to perform further investigation regarding your SSL VPN and WAF conflict. Please raise a support case and PM me with your case number.

    Thanks!

  • Any info on how this is going?

    We were finishing the configuration of XG when I found out we cannot have the same port for WAF and SSL VPN like you can do in UTM! Not sure what to do now, throw away months of work or what really...

    I believe allowing to select the interface to listen in OpenVPN, like you can do in UTM, would solve it. I don't know how XG got into production without this, port 443 can't be used for anything.

Reply
  • Any info on how this is going?

    We were finishing the configuration of XG when I found out we cannot have the same port for WAF and SSL VPN like you can do in UTM! Not sure what to do now, throw away months of work or what really...

    I believe allowing to select the interface to listen in OpenVPN, like you can do in UTM, would solve it. I don't know how XG got into production without this, port 443 can't be used for anything.

Children