Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

No Access to new VPN Portal

Hi everyone, I have updated my XG to the new SFOS 20 and set everything up according to the knowledgebase article. When I now go to my URL "">https://firewall.my_Domain.de", I get a "forbidden"

I also have a WAF rule that points to my bookstack. As soon as I deactivate this WAF rule, I can also access the VPN portal.

I thought the 443 port can be shared with the new VPN portal!

I access my Bookstack instance via "">bookstack.my_Domain.de".
I want to access the VPN portal via "">firewall.my_Domain.de".

Here is a screenshot of the WAF rule.

Can someone tell me where my error lies?

Thank you.



This thread was automatically locked due to age.
  • Hello  ,

    Thank you for reaching out to the community, there are some restrictions SSL VPN traffic and WAF rules must have different values for at least one of the following objects: WAN IP address, port, protocol.  SSL VPN traffic to the WAN IP address used by WAF rules is dropped if it shares a common port and protocol with the WAF rules. This applies only to IPv4 traffic. The default HTTPS ports differ for WAF rules (443) and SSL VPN (8443). WAF traffic always uses the TCP protocol. But you can not use the same port for the VPN Portal. Here's an example of the configuration SSL VPN traffic can use when the network has two WAN IP addresses:

    Thanks & Regards,
    _______________________________________________________________

    Vivek Jagad | Team Lead, Global Support & Services 

    Log a Support Case | Sophos Service Guide
    Best Practices – Support Case


    Sophos Community | Product Documentation | Sophos Techvids | SMS
    If a post solves your question please use the 'Verify Answer' button.