<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Restrict SSL VPN to WAN Alias</title><link>https://community.sophos.com/sophos-xg-firewall/f/discussions/148028/restrict-ssl-vpn-to-wan-alias</link><description>I&amp;#39;m trying to configure an SSL VPN. Our WAN subnet has 5 IP addresses, with 4 aliases set up for the additional IPs: 
 
 Port2 
 Port2:0 
 Port2:1 
 Port2:2 
 Port2:3 
 
 Currently, I have a web server running on Port2:0 . 
 I want the SSL VPN to run</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Restrict SSL VPN to WAN Alias</title><link>https://community.sophos.com/thread/548795?ContentTypeID=1</link><pubDate>Tue, 19 Nov 2024 04:57:50 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ab420193-038b-43fc-8c11-5da9d0b18e93</guid><dc:creator>Hardik_R</dc:creator><description>&lt;p&gt;Hi&amp;nbsp;&lt;a href="/members/brennan-kostyniuk"&gt;Brennan Kostyniuk&lt;/a&gt;&amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p&gt;You can try creating a Local ACL&amp;nbsp;Administration &amp;gt; Device Access &amp;gt;&amp;nbsp;&lt;span&gt;Local service ACL exception rule &amp;amp; drop SSL VPN traffic destined to those Alias.&lt;br /&gt;&lt;a href="https://docs.sophos.com/nsg/sophos-firewall/21.0/Help/en-us/webhelp/onlinehelp/index.html?contextId=add-local-service-ACL"&gt;Add local service ACL exception rule&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>