Description
Scope
FortiGate.
Solution
It is important to know that on some broadcast services, the server will send the reply on a broadcast IP.
The above policy will allow both sessions:
DMZ_in 10.44.5.23.57 -> 255.255.255.255.57: udp 20
Broad_out 10.44.5.23.57 -> 255.255.255.255.57: udp 20
Broad_in 10.56.5.5.57 -> 255.255.255.255.57: udp 20
DMZ_out 10.56.5.5.57 -> 255.255.255.255.57: udp 20
Enable logging on the multicast policy to see the traffic logs under Log & Report -> Multicast Traffic.
Note: This configuration might have worked in earlier versions, but it is not supported in the latest releases (verified in 7.4.8). The explanation is as follows:
The broadcast-forward enable option is used to control direct broadcasts, not traffic destined for 255.255.255.255. Therefore, it is not possible to allow traffic to 255.255.255.255.
For example, if the DMZ interface is configured with the subnet 192.168.0.0/24, the directed broadcast address would be 192.168.0.255.
For a detailed explanation, see Troubleshooting Tip: FortiGate Operating in NAT Mode does not allow Broadcast Traffic destined to 25....
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.