Skip to main content
salassilvaj
Explorer III
July 15, 2025
Question

SDWAN TCP-UDP ports fort ipsec tunnel used behind nat

  • July 15, 2025
  • 1 reply
  • 777 views

Does someone know which ports are used for vpn ipsec tunnel under sdwan scenario considering this fortigate is behind a NAT ISP connection? apart from UDP 4500 and 500 ports which one are require to allow it.

1 reply

AEK
SuperUser
SuperUser
July 15, 2025

Yes, only UDP 500 and 4500 are used.

Starting from 7.4.1 you can customize it on TCP.

https://docs.fortinet.com/document/forticlient/7.4.0/new-features/914884/ipsec-vpn-over-tcp-7-4-1

AEK
salassilvaj
Explorer III
July 15, 2025

for ssl vpn dial up connection are same ports? ISP firewall must allow only these ports ? or only the ports assigned through the forti config

AEK
SuperUser
SuperUser
July 15, 2025

SSL VPN port is 443 or 10443 (usually default values).

For SSL VPN security it is recommended to change it to a high non standard port.

The ISP firewall must allow the port numbers you have configured for IPsec and SSL VPN if you want them to be reachable.

AEK