Hey everyone. I see that the question of restricting access to the Gaia web interface from public IP's has been asked and answered many times, but what happens when Remote Access VPN is in use on the appliance, and port 443 needs to be publicly available in order to facilitate the VPN connection? Is the easiest way to change the Gaia web interface port to use something custom, and not related to the VPN negotiation at all, and then make sure that port is blocked in the rulebase for anything except admin machines?
This recently appeared in a pentest, and was flagged as a high priority issue.