FortiOS and SNAT: Excessive reuse of Source Ports
Hello,
I have devices in LAN (APs) that creates two connections to the same Public IP (CAPWAP Control Channel: UDP/5246 + CAPWAP Data Channel UDP/5247)
Both connections have the same port as Source Port: 5270, this is the behavior I get with FortiOS 7.2:

--> The Gate is assigning the same SRC port (5270) to two different flows intended for the same IP target (where, however, the destination-port differs)
I realized that surely this comportment is the child of how FortiOS selects unused NAT ports,
but do you think there is a configuration that would allow me to have SOURCE PORT was Always changed for an SPECIFIC DESTINATION?
The Host on the on the other hand side is not able to distinguish the traffic if it comes from Capwap-DATA or Capwap-CTRL if it comes from the same src-port (and obviously same src-ip)
But now that we know the Host Target limitation, my question is how can I change the port assignment logic in SNAT on my FortiGate
Thanks!
