This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Change SSL VPN Port

Is it possible to change the SSL VPN Port for Remote Access??

... and for the User Portal, too?



This thread was automatically locked due to age.
Parents
  • Hi,

    Under System > Administration > Settings
    Change the "User Portal HTTPS Port" port, this port too will be used for SSL VPN remote connection.

    __

    Analyst at Tecnomega
    Cyberoam Certified Network & Security Expert (CCNSE)

  • Hello, is there a way to change the port ? In the road map maybe?

  • Hi Scale, I hope its in soon because it is a requirement!

  • Hi Scaledem,

    indeed we have a request to make SSLVPN port changeable in our backlog. So this feature will be implemented. I am not quite sure how fast we will be able to deliver you this feature, but it is definitly planned with major priority.

    Greetings

    Holger

  • Bump.  The XG appliances need this feature sooner rather than later.  UTM9 and SG both had the option and now we have clients complaining that the feature is missing.  They are threatening to either go back to UTM9 or worse yet, move to a new vendor.

    Please escalate the urgency of this request!  I am also testing v16 and noticed that it hasn't made it into that update yet either.

  • Bump.  Throwing in my request for this ASAP as well. This a pretty major requirement with more and more places locking down their networks these days.

  • Thanks for the above. This was quite helpful as a workaround to get SSL VPN working for me. 

    For some reason, my instance of XG did not seem to have the "Non-HTTP Based Policy", so I used the "DNAT/Full NAT/Load Balancing" template with the following settings:

    For "Destination Host/Network", #PortB is my WAN port, while "Protected Server" is the LAN IP address for Sophos XG. 

    It seems to work OK. 

    One thing that surprised me a bit is protocol Selection under "Destination & Services". I would have though there would be an option to forward both TCP and UDP, and not just one or the other, but apparently you can't. Does that mean if I wanted both to be covered off, I would need two rules, one for TCP and another for UDP? That seems rather inefficient and a bit of unnecessary pain. Or did I just miss something to enable both?

    I had initially tried UDP but that didn't seem to work behind an offsite firewall, so changed to TCP. When UDP is selected, the User Portal can still be accessed. Unfortunately, where I am they block UDP on 443 apparently, so I had to switch to TCP. Of course, doing this kills access to the User Portal from the internet, which is a bit of an irritation. It can still of course be accessed once the VPN is connected. That being said, if anyone knows a workaround so that both the User Portal and VPN are accessible (other than using 80 for the former), your thoughts would be most appreciated. 

  • Does this still work for you @MarcBorgers it doesn't seem to work anymore in the most recent Sophos XG.

  • FWIW on the most recent firmware update (16.05.3 MR-3) the port forwarding suggested by Marc also no longer seems to work for me.

    Chris Schnobb said:

    Does this still work for you @MarcBorgers it doesn't seem to work anymore in the most recent Sophos XG.

     

  • @MarcBorgers I tried this but it's not working !!

  • Hi SecuredNet,

     

    the feature you are requesting will be shipped with SF 17.1 which is currently under testing and will hopefully releases soon.

     

    Regards,

    Holger

Reply Children