# FMS19.4 Admin Console Port changed

**URL:** <https://the.fmsoup.org/t/fms19-4-admin-console-port-changed/2579>\
**Category:** Heads-Up!\
**Tags:** admin-console\
**Created:** [November 16, 2021, 7:41pm UTC](https://the.fmsoup.org/t/fms19-4-admin-console-port-changed/2579 "2021-11-16T19:41:10Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![FileKraft](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/filekraft/32/1183_2.png) [@FileKraft](https://the.fmsoup.org/u/FileKraft)\
**Post date:** [November 16, 2021, 7:41pm UTC](https://the.fmsoup.org/t/fms19-4-admin-console-port-changed/2579/1 "2021-11-16T19:41:10Z")

</div>

- Admin Console is now accessible remotely using https:// _[server\_address]_ :443/admin-console instead of https:// _[server\_address]_ :16000/admin-console.

---

<div class="post-metadata">

**Author:** ![MonkeybreadSoftware](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/monkeybreadsoftware/32/361_2.png) [@MonkeybreadSoftware](https://the.fmsoup.org/u/MonkeybreadSoftware)\
**Post date:** [November 16, 2021, 8:13pm UTC](https://the.fmsoup.org/t/fms19-4-admin-console-port-changed/2579/2 "2021-11-16T20:13:35Z")

</div>

And I think you can configure whether you like to have it exposed to the world there or not, e.g. limit access to local network.

---

<div class="post-metadata">

**Author:** ![Malcolm](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/malcolm/32/196_2.png) [@Malcolm](https://the.fmsoup.org/u/Malcolm)\
**Post date:** [November 16, 2021, 8:56pm UTC](https://the.fmsoup.org/t/fms19-4-admin-console-port-changed/2579/3 "2021-11-16T20:56:25Z")

</div>

In other words, it is on the default HTTPS port.

That's an improvement. One less thing to manage on the network. 🏆

Also, no need to type the port number when you are accessing the console via the browser. 👍

---

<div class="post-metadata">

**Author:** ![iwitschi](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/iwitschi/32/709_2.png) [@iwitschi](https://the.fmsoup.org/u/iwitschi)\
**Post date:** [November 22, 2021, 9:47am UTC](https://the.fmsoup.org/t/fms19-4-admin-console-port-changed/2579/4 "2021-11-22T09:47:27Z")

</div>

Well, rather IP-restrict that path by default. Here is a howto from Claris: [ClarisPKB](https://support.claris.com/s/article/Protecting-FileMaker-Admin-Console-port-443-from-brute-force-attacks?language=en_US)  
They didn't introduce a protection mechanism like slowing down multiple login attempts, nor any IP-restriction possibilities 🤔

---

<div class="post-metadata">

**Author:** ![Malcolm](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/malcolm/32/196_2.png) [@Malcolm](https://the.fmsoup.org/u/Malcolm)\
**Post date:** [November 22, 2021, 6:31pm UTC](https://the.fmsoup.org/t/fms19-4-admin-console-port-changed/2579/5 "2021-11-22T18:31:14Z")

</div>

Thanks for adding the link to the article @iwitschi. That's good information. 😀

---

<div class="post-metadata">

**Author:** ![AndyHibbs](https://yyz2.discourse-cdn.com/flex030/user_avatar/the.fmsoup.org/andyhibbs/32/3089_2.png) [@AndyHibbs](https://the.fmsoup.org/u/AndyHibbs)\
**Post date:** [November 24, 2021, 7:34am UTC](https://the.fmsoup.org/t/fms19-4-admin-console-port-changed/2579/6 "2021-11-24T07:34:29Z")

</div>

As with all IT information, there is an assumption of too much knowledge within these instructions. I’ve just secured 4 Windows servers on the cloud that, as a result of this FMS 19.4.1 update, have had their admin console publicly available on the Internet for the first time in over 10-years.

I’ve found that the published didn’t work:

```
            <rule name="fac_restrict" patternSyntax="Wildcard" stopProcessing="true">
	<match url="*"/>
	<conditions>
    <add input="{URL}" pattern="admin-console" />
    <add input="{REMOTE_ADDR}" pattern="192.168.1.1" negate="true" />
 </conditions>
	<action type="CustomResponse" statusCode="403" statusReason="Forbidden: Access is denied."
    statusDescription="You do not have permission to view this directory or page." />
</rule>

```

(192.168.1.1 entered as an example server IP address. We only require the admin console to be available on the server FMS is running on).

After much testing the best we achieved was to have the admin console unavailable along with WebDirect unavailable.

To add a bit more detailed information, the configuration file that has to be changed is at:

C:\Program Files\FileMaker\FileMaker Server\HTTPServer\conf

Open this in Notepad run as Administrator, otherwise changes cannot be saved

We pasted our revised syntax just above (formatting added below otherwise the syntax isn’t displayed) :

```auto
  </rules>
	  <outboundRules>

```

```auto
(i.e. at the end of <rules>)

```

We replaced "admin-console" with

```auto
"*admin-console*"

```

The wildcards either side changed the behaviour so that we can only access the admin console from within the server, external access via port 443 (or any port via the firewall) is now disabled and WebDirect works.

To sum up, our syntax is (for a server with an IP address of 192,168.1.1 - a wild card such as 192.168\* could be used):

```
            <rule name="fac_restrict" patternSyntax="Wildcard" stopProcessing="true">
	<match url="*"/>
	<conditions>
    <add input="{URL}" pattern="*admin-console*" />
    <add input="{REMOTE_ADDR}" pattern="192.168.1.1" negate="true" />
 </conditions>
	<action type="CustomResponse" statusCode="403" statusReason="Forbidden: Access is denied."
    statusDescription="You do not have permission to view this directory or page." />
</rule>

```

Hope this prevents someone going to bed after midnight and getting up at 05:00 to secure their servers 😉

Kind regards  
Andy
