Skip to main content
michale65
New Member
February 27, 2023
Question

Correlation Source Port of local-in to forward policy - Fortigate Explicit Proxy

  • February 27, 2023
  • 1 reply
  • 914 views

Hi!

I am just struggeling with the correlation of my logs. Currently, I am using Fortigate 6.4.11 with Explicit proxy

Local-In-Policy is showing the "original" source port and IP of every connection.

But: I am not able to do any correlation between the outgoing "forward-proxy-policy"-log entry and the original "local-in-policy"-log-entry.

Are you aware of any possibility to do this?

Background: I am using Linux terminalservers. As there is no Linux-terminalserver-agent, I have to find out which user did open e.g. a malicious URL. The linux EDR is showing the source-port for every user, but the source-port of the "forward-policy", that is showing up, that the malicious URL has been opened is not the original source-port

Thank you for your help

1 reply

gfleming
Staff
Staff
February 27, 2023

If i understand your issue correctly you can try setting "set fixedport enable" in your firewall policy. This will prevent the FortiGate from changing the source port in the outbound, Source-NATted packet.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!