SSL VPN client ports

Showing results for 
Show  only  | Search instead for 
Did you mean: 

SSL VPN client ports

L0 Member

We have a few officers that connect from a remote location with a firewall of its own.  They are all using the SSL VPN client to connect back to home.  I can pull up the https://external-ip and login, but when the connection starts up i get a Disconnected; unable to connect to remote client.

I need to know what ports the SSL VPN client uses to connect back to our firewall so I can tell the IT guy what ports to open.

Thanks in advance!


L0 Member

Also high priority, the people using this VPN can't do their reports unless they have the VPN connection.

If you do not have IPsec enabled, SSL VPN will use TCP 443.  If IPSec is enabled. TCP 443 will be used for authentication and the traffic will use UDP port 500.

I believe UDP port 4501 is used for the UDP encapsulated ESP (IPSEC) transit channel.



L0 Member

We disabled IPsec on our PA500.  Tried reconnecting the SSL Client but still getting the same error.  I can see the clients attempting to connect but are never assigned an IP address from my SSL pool; but other clients are getting IP addresses.  Is it possible that 443 is used for authentication and another port is used for data ?

Is there a debug command i can use to view authentications and data coming into the firewall?

Kelly is correct, IPSEC uses 4501.  With IPSEC disabled the traffic does use 443 and is identified as web-browsing. A couple of commands to look at authentication and traffic are:

>show ssl-vpn current-user - to show who is logged in.  You can also type portal <name> after the command to see who is logged in by portal.

>show log system subtype equal sslvpn - to show all ssl vpn authentication and connection requests.

You may want to disable antivirus or the firewall on the clients with the problem.  If you are unable to resolve, please contact your support provider to troubleshoot.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!