Skip to main content
scheuri1
New Member
June 16, 2025
Question

Local-In-Policy blocks ipsex dialup on TCP/443 requests from my IP

  • June 16, 2025
  • 1 reply
  • 787 views

Hi all

I am trying to setup ipsec dialup (IKEv2) using port tcp/443 on a FGT200G with 7.4.8 and with Forticlient (vpn only version) 7.4.3.
Amongst other issues, I am facing a connection block (not negotiation error, I seem not to get that far).
My connections requests from my client (and from my IP) are seen on the fortigate (on port tcp/443) as expected, but are being blocked by local-in-policy number 0.

 

I have added one single local-in-policy that should allow ssh, icmp and https (which is tcp/443 in the service object) from my IP address.

 

ICMP works and the FGT replies for my IP, however, tcp/443 is being blocked,

As this is all in one single local-in-policy, I have no idea where I went wrong - ICMP works, so why doesn't tcp/443?

 

Thanks for giving me a hint where to look

Best regards

 

1 reply

Toshi_Esumi
SuperUser
SuperUser
June 16, 2025

A couple of things you can try. 
1. temporarily remove/disable all local-in-policy for test purpose. You probably need to do that in a maintenance window.
2. change the port from 443 to something else like 11443.
If either of them doesn't work, something else is causing it.

 

Toshi 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!