Created on
05-01-2025
06:47 AM
Edited on
06-22-2025
01:05 PM
By
Jean-Philippe_P
Description | This article describes changes required in FortiDDoS based on FortiOS migration from SSL VPN to IPsec VPN in FortiOS Release v7.6.3. |
Scope | All FortiDDoS-B/E/F. |
Solution |
In all cases below, contact FortiCare Support if assistance is needed.
There are 2 ways IPsec works in a network:
Both variants above also use IKE over UDP Port 500 for setup and key exchange.
If Protocol 50, UDP Port 4500, or UDP Port 500 are not currently in use, FortiDDoS has low thresholds for these parameters. After FortiOS upgrade, traffic on Protocol 50, UDP 4500, and/or UDP 500 may increase substantially in the firewall or VPN Server SPP,s resulting in VPN impairment or failure.
Modifying FortiDDoS Thresholds for the above conditions: The following instructions may show changes based on platforms and Releases. If no platform or release is shown, the change applies to all.
Before modifying FortiOS VPN settings, place any SPPs with firewalls and/or VPN servers into Detection Mode so VPN traffic will not be affected. If unsure, place all SPPs in Detection Mode.
After changing FortiOS VPN settings:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.