Troubleshooting Tip: How to resolve Blocked port detected by online Port Checker despite correct VIP configuration and firewall policy in FortiGate
| Description | This article describes how to resolve blocked ports by checking the port status of the internal server. |
| Scope | FortiGate v7.0.11 and above, v7.2.1 and above. |
| Solution | When using an online port checker, the port used for services of the internal server is indicated as blocked.
To troubleshoot this :
Example of problem: In this example, 111.111.111.111 is an external WAN IP and 10.10.10.10 is a mapped internal server IP.
config firewall vip (Vip is set correctly)
config firewall policy (firewall policy is set correctly)
#Allow incoming TCP ports TCP_IN = “20,21,80,443,3306”
|

