Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RS_Daniel
Advisor

Remote Access port 80 needed?

Hi CheckMates,

We have a clusterXL with 2 X 1800 appliances, running gaia embedded R81.10.17. This cluster is used for remote access vpn connections.

VPN clients face an issue. When they try to connect, site is not responding error appears. Checking on logs, we can see port 80 is dropped by our clean up rule.

If we create a explicit rule allowing port 80 from client public IP, the connection is successful. So i have two questions: Is it normal remote access vpn clients use port 80? if it is normal, i think it should be accepted by default, rigth?

We have the option "Accept Remote Access control connections" enabled on global properties. Any help is appreciated thanks in advance.

Regards

0 Kudos
9 Replies
PhoneBoy
Admin
Admin

It's normal for the client to reach out on port 443.
Port 80 should redirect there.

0 Kudos
RS_Daniel
Advisor

Hi,

Thans for your help. So, in our case, redirection is not working? as vpn clients connections are dropped on port 80.

0 Kudos
PhoneBoy
Admin
Admin

If you don't allow access on port 80, that redirect won't happen.
Why the client is using port 80 is a separate question. 
What client version on what platform(s)?

0 Kudos
RS_Daniel
Advisor

The happens with many different client versions on windows. In my case i am using endpoint security E89.00 and windows 11. On the other hand, i have a couple dozens different customers with similar scenario, and i can connect to all of them without problems, without allowing port 80 with an explicit rule.

0 Kudos
the_rock
Legend
Legend

How is below setup? Btw, I would test with newest E89 client. I can verify in the lab for that behavior. How are you creating/connecting to site? Is site name something like vpn.companyname.com:80?

Andy

0 Kudos
RS_Daniel
Advisor

The configuration is the same as on the screenshot, https and all interfaces. To connect the clients use vpn.domain.com or the public IP address, without port. In both cases the same issue.

Regards

0 Kudos
the_rock
Legend
Legend

This is very interesting...let me finish some Cisco stuff Im doing, will definitely confirm this in the lab later.

Andy

0 Kudos
the_rock
Legend
Legend

I just tested and worked fine in my lab, mind you, port 80 is allowed, which would make sense, since redirect does happen.

Andy

0 Kudos
the_rock
Legend
Legend

I am 100% sure what @PhoneBoy said is correct.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events