FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jbindra
Staff
Staff
Article Id 364559
Description This article describes how the SSL VPN port works when an external port scan is done on the WAN interface.
Scope FortiGate.
Solution

In certain scenarios while running port scanning on an external interface where SSL VPN is also set up, there is a high chance that the port scanner will show that the SSL VPN port is open on FortiGate.

 

For example, if the SSL VPN listening interface is set to the WAN interface and there is a custom port (example: port 10443) set for this request, then the external port scanner will show that port 10443 is open on FortiGate.

 

port open fgt.PNG

 

Run nmap (external port scanner) on the WAN interface of FortiGate. It will show port 10443 as open:

 

open port kali.PNG

 

Note: This port cannot be disabled on the FortiGate even if the web mode is disabled, since the FortiGate is set to listen for traffic requests coming from Tunnel mode (FortiClient) on this particular port. 

 

There is no way to completely disable this listening port.