Hello,
I am a new XG Firewall Home User and I have been reading how to setup XG Firewall OpenVPN to publish the VPN though port 443 without impacting the ability to publish web applications on 443 through WAF. As I understand, this is not possible at the moment (even with v18). As I read, it is somehow possible with UTM9 though. I was surprised to see this was not available on XG (I come from using TMG 2010 where you can do port sharing (WAF + SSTP thru TCP 443)).
By reading threads like this one below, I read there’s people trying to overcome this issue by having the VPN server on a different box, and have XG firewall DNAT to it on port 443 (either TCP or UDP).
I understand this sounds like an overkill, but using a port different than 443 for VPN seems too restrictive due to the way firewalls block most of the other ports. I’d like to give this a try and see how it works. My setup is:
VPN Server (XG Firewall just for the VPN):
- WAN: 10.20.20.1 (DMZ Network)
- Port 443 TCP or UDP (based on performance and compatibility).
- Certificate used: Public domain cert.
- Hostname: public FQDN
XG Firewall (Internet Facing):
- DMZ: 10.20.20.254
- DNAT (TCP or UDP 443) to 10.20.20.1. (DMZ Network).
When I test this, on the VPN client log I see: CONNECTION TIMEOUT.
On the XG Firewall Log (Internet Facing), I see: Invalid Packet.
Has anyone done this successfully? Thoughts?
Thanks!
This thread was automatically locked due to age.