Is it possible to change the SSL VPN Port for Remote Access??
... and for the User Portal, too?
This thread was automatically locked due to age.
FWIW on the most recent firmware update (16.05.3 MR-3) the port forwarding suggested by Marc also no longer seems to work for me.
Chris Schnobb said:Does this still work for you @MarcBorgers it doesn't seem to work anymore in the most recent Sophos XG.
@MarcBorgers I tried this but it's not working !!
Hi SecuredNet,
the feature you are requesting will be shipped with SF 17.1 which is currently under testing and will hopefully releases soon.
Regards,
Holger
Hi guillaume,
port sharing is possible, so you can use port 443 for user portal and SSLVPN.
Best regards,
Holger
Hi SecureNet,
just in case you have not seen yet. In the current version of SFOS 17.1, this feature is implemented.
Best regards,
Holger
I have tried to change the port from 8443 to 443 using UDP mode and it fails saying there is a conflict on that port.
Everything else on the XG is using port 443 is TCP, e.g. WAF.
Can you confirm this is a bug, or how to fix it? It is a significant benefit to have the UDP443 for SSL VPN and TCP443 for WAF
Thanks
Ian
Hello.
Yes I moved the user portal from 443 to 444 when I tried it, and I have just tried again now with no luck
I get the red pop up box saying "The selected Port is already used by another service. Please choose a different Port."
Thanks
Ian
Also tried, you can not use 443 tcp or udp for vpn ssl and/or user portal since you activate a waf with https rule (and the contrary)
should be great if sophos let choice on which port/public ip vpn ssl and user portal listen as it could be possible to have waf on one port/ip AND ssl vpn on an other port/ip.
but it's not the case..
Hello,
I can use 443 for WAF and User Portal, this is my normal configuration. I assume this is because WAF is only available on WAN IP And User Portal from various local interfaces.
As SSL VPN can use all interfaces, I assume this has an effect on why it cannot be enabled. On that note, I have just disabled SSL VPN from ALL interfaces and tried again, but still an error.