Is it possible to change the SSL VPN Port for Remote Access??
... and for the User Portal, too?
This thread was automatically locked due to age.
In Version SFOS 17.1.0 GA, now you can change the port for User Portal and SSL VPN as well from default port 443 to any as per your desire.
Reference release note:-
https://community.sophos.com/products/xg-firewall/b/xg-blog/posts/sfos-17-1-0-ga-released
Regards,
Imran
Hello Imran,
I know the new feature has been added to do this. My original post onto this thread (page 5 iirc) and the subsequent discussion was because of the fact that this new feature seems to have an issue...
If you are using WAF / User Portal on TCP 443 you still cannot set the vpn to UDP 443, but you can still change it to other ports.
Hello Ian,
I complete agree from you, it is restricted with User Portal only. you may use 443 for SSL VPN and WAF at same time but not with User Portal.
Currently i am using it by changing the User Portal Port only.
Regards,
Imran
Can you please share how you made that work?
I have User portal on 444, WAF on 443 and SSL VPN on 8443. When I try to change SSL VPN to 443 (UDP) it says the port is already used.
If I change the WAF port to something else, SSL VPN can be changed to 443 without issues. So I would really love to know how you managed to habe SSLVPN and WAF on the same port. I can live with user portal on a different port.
Thanks!
Hi,
were you able to set the WAF back to 443 after you had the SSL VPN on 443?
Hi,
were you able to set the WAF back to 443 after you had the SSL VPN on 443?
No, I can't. Just tested it. If I change SSL VPN to 443 (UDP), when I try to change WAF to 443 it says the port is used elsewhere.
The user portal is in port 444 so it's not interfering.
Hi all,
It is possible to have SSL VPN and User Portal on Port 443.
It is not possible to have SSL VPN / User Portal and WAF the same port.
SSL VPN and User Portal can share the same port.
As far as i know, we are currently working on this.
Thanks for clearing that up.
Do you have a rough ETA? I think we will have to cancel our migration for the second time until this is available
I am not aware of a ETA for this.
currently, if somebody is running into this limitation, i am using 10443 for SSL VPN or leave 8443 for ssl vpn and using a DNAT trick with another appliances.
So simply DNAT 443 SSL VPN to Interface A to another XG / appliance and DNAT it 8443 to XG or use another appliance for SSL VPN only on Port 443.
It is not the best Solutions but it works fine until the change / port sharing is possible.
I only have an HA cluster (active/passive) of XG, so that shouldn't be possible. I will have to go back to UTM or use a different port for SSL VPN. I don't know what's worse at this point.