What I was personally referring to was when you go to gateway section for visitor mode, select say random port ( NOT https). You can create another port, say 4443 and select it there, and then when you attempt to use endpoint client, just have people add :4443 to IP or fqdn when connection....so say if your external IP resolves to vpn.mycompany.com, you would try connect from endpoint client by creating new site as vpn.mycompany.com:4443...though since its SMB appliance, Im not really that verse in those appliances, so not sure if that option would be same as regular non smb firewalls.
Can you try that way?