<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Custom HTTPS port not showing up in URL</title><link>https://community.sophos.com/utm-firewall/f/web-server-security/115637/custom-https-port-not-showing-up-in-url</link><description>I am trying to publish an internal web server over the WAF. The setup is as follows: 
 
 Internal name : server.company.local , reachable via Port 8089. 
 External name : server.company.com (I have a public DNS record pointing to my static public ip)</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: Custom HTTPS port not showing up in URL</title><link>https://community.sophos.com/thread/416858?ContentTypeID=1</link><pubDate>Wed, 09 Oct 2019 23:13:46 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:4ed6d22f-860c-4eba-ab69-e954db333422</guid><dc:creator>admin888</dc:creator><description>&lt;p&gt;Well that was easy. Your option 2 worked out perfectly, and the site is displaying properly too now. Thank you.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Custom HTTPS port not showing up in URL</title><link>https://community.sophos.com/thread/416857?ContentTypeID=1</link><pubDate>Wed, 09 Oct 2019 23:07:25 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:f2c98cce-4e7a-415e-ba68-d4e1f97b3532</guid><dc:creator>DouglasFoster</dc:creator><description>&lt;p&gt;On closer consideration, I think the most important option is &amp;quot;Rewrite HTML&amp;quot; on the Virtual Webserver object.&amp;nbsp; It is right next to &amp;quot;pass host header&amp;quot;.&amp;nbsp; &amp;nbsp;Your problem is that the urls are not being rewritten to external syntax.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Custom HTTPS port not showing up in URL</title><link>https://community.sophos.com/thread/416851?ContentTypeID=1</link><pubDate>Wed, 09 Oct 2019 21:32:43 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:5a49303e-9446-47b8-83e7-f9156085c46e</guid><dc:creator>DouglasFoster</dc:creator><description>&lt;p&gt;Not exactly sure why you have this problem, but here are two things to try:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Option 1&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;I am pretty sure that &amp;quot;HTTPS and Redirect&amp;quot; means that it accepts HTTP connections on port 80 but redirect to HTTPS on whatever port.&amp;nbsp; &amp;nbsp;This might be creating confusion.&amp;nbsp; Try changing to HTTPS (without redirect) and see if the problem goes away.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Option 2&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If you have WAF in front of your Exchange server, you can get rid of the custom port on the public IP using Server Name Indication (SNI)&lt;/p&gt;
&lt;p&gt;1) WAF on exchange.example.com:443 (public a.b.c.d) redirects to internal Exchange:443 (10.10.10.10)&lt;/p&gt;
&lt;p&gt;2) WAF on&amp;nbsp; otherapp.example.com:443 (public a.b.c.d) redirects to internal Otherstuff:8089 (10.10.10.11).&amp;nbsp;&lt;/p&gt;
&lt;p&gt;I perceive the second approach as preferable because the users are more likely to enter the URL correctly in the address bar or Favorites entry.&lt;/p&gt;
&lt;p&gt;Curious to hear your results.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Custom HTTPS port not showing up in URL</title><link>https://community.sophos.com/thread/416840?ContentTypeID=1</link><pubDate>Wed, 09 Oct 2019 19:22:48 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:ebd6a278-7baf-4b72-9ade-368ef410af98</guid><dc:creator>Peter-Paul Gras</dc:creator><description>&lt;p&gt;It shouldn&amp;#39;t be a problem having more than one server listening on the external 443 port. The mapping is done by WAF based on the certificate and the real server.&lt;br /&gt;I host several external domains all resolving to one IP / port 443&lt;br /&gt;Internally they are mapped to ports 8281, 8282 etc.&lt;/p&gt;
&lt;p&gt;Grtz, Peter-Paul&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Custom HTTPS port not showing up in URL</title><link>https://community.sophos.com/thread/416834?ContentTypeID=1</link><pubDate>Wed, 09 Oct 2019 17:28:33 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:8a51aee2-15a9-4897-aa0b-8e6d3e5f1ddc</guid><dc:creator>admin888</dc:creator><description>&lt;p&gt;Good point, I can try that. Meanwhile I&amp;#39;ve managed to access the links by manually adding the port to the URLs and the site is all screwed up (landing and login page were fine). I think the Javascript on those pages might cause problems for the WAF (I did try rewrite HTML on/off and no firewall profile).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Custom HTTPS port not showing up in URL</title><link>https://community.sophos.com/thread/416832?ContentTypeID=1</link><pubDate>Wed, 09 Oct 2019 17:01:00 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:fbab2cfc-b67f-44a4-a170-c84311b398f1</guid><dc:creator>BAlfson</dc:creator><description>&lt;p&gt;What if you change the Real Server to work with 443 and leave the Virtual Server on 8089?&lt;/p&gt;
&lt;p&gt;Cheers - Bob&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Custom HTTPS port not showing up in URL</title><link>https://community.sophos.com/thread/416736?ContentTypeID=1</link><pubDate>Tue, 08 Oct 2019 14:31:12 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:7c82d2a9-452a-43bd-afb3-1357dd161944</guid><dc:creator>admin888</dc:creator><description>&lt;p&gt;I already use Port 443 for Exchange services and only have one public IP address, so I&amp;#39;m guessing the only other option here is DNAT?&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Custom HTTPS port not showing up in URL</title><link>https://community.sophos.com/thread/416579?ContentTypeID=1</link><pubDate>Sun, 06 Oct 2019 19:40:10 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:68b40f7f-beb4-4be7-b79f-734b199a2bf9</guid><dc:creator>dirkkotte</dc:creator><description>&lt;p&gt;UTM/SG don&amp;#39;t support rewriting URL this way ... as i know.&lt;/p&gt;
&lt;p&gt;i would try to use Port 443 for Virtual webserver (if not used already).&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>