Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
cdooer
Contributor
Jump to solution

Restrict Access to Gaia Web Interface When RAVPN is in use

Hey everyone. I see that the question of restricting access to the Gaia web interface from public IP's has been asked and answered many times, but what happens when Remote Access VPN is in use on the appliance, and port 443 needs to be publicly available in order to facilitate the VPN connection? Is the easiest way to change the Gaia web interface port to use something custom, and not related to the VPN negotiation at all, and then make sure that port is blocked in the rulebase for anything except admin machines?

This recently appeared in a pentest, and was flagged as a high priority issue. 

0 Kudos
1 Solution

Accepted Solutions
Lesley
MVP Gold
MVP Gold

GAIA web portal cannot run on the same port if 443 is needed for visitor mode (RAVPN).

You need to change the GAIA portal port to something different. You have to do this via clish or web interface and after that also change the platform portal in SmartConsole under the firewall object. 

image.pngimage.png

Example clish config:

cp-mgmt> set web ssl-port 4434

-------
Please press "Accept as Solution" if my post solved it 🙂

View solution in original post

2 Replies
Lesley
MVP Gold
MVP Gold

GAIA web portal cannot run on the same port if 443 is needed for visitor mode (RAVPN).

You need to change the GAIA portal port to something different. You have to do this via clish or web interface and after that also change the platform portal in SmartConsole under the firewall object. 

image.pngimage.png

Example clish config:

cp-mgmt> set web ssl-port 4434

-------
Please press "Accept as Solution" if my post solved it 🙂
PhoneBoy
Admin
Admin

Yes, you can change the port via clish: set web ssl-port xxxx
You can also use System Configuration > Host Access to restrict what IPs are allowed to connect (independent of the firewall policy).
Believe this also applies to SSH. 

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events