FGT Local In Policy Allows UDP 1144 and 3799 for all ports - Details?
Hi All,
As I step through locking down a new FortiGate 300D, 5.4.1, I've turned on the feature to display Local In Policy for the GUI to look at what services/ports are open by default. Most of what I see makes sense, and matches to either the 5.4 docs, http://docs.fortinet.com/d/fortios-ports-and-protocols, or to previous versions like http://docs.fortinet.com/uploaded/files/1880/FortinetOpenPorts.pdf.
However, local in policy shows UDP 1144 and UDP 3799 as allowed for all ports, including wan ports, and I can't find any information on these ports, except that TCP/UDP 3799 might be used for radius-dynauth (though that doesn't match the RADIUS ports listed in the Fortinet docs). Perhaps they're something related to the new security fabric? Without knowing what these are for I'm uncomfortable leaving them open on wan ports.
Anybody have more information on UDP 1144 or UDP 3799?
