Description | This article describes how the SSL VPN port works when an external port scan is done on the WAN interface. |
Scope | FortiGate. |
Solution |
In certain scenarios while running port scanning on an external interface where SSL VPN is also set up, there is a high chance that the port scanner will show that the SSL VPN port is open on FortiGate.
For example, if the SSL VPN listening interface is set to the WAN interface and there is a custom port (example: port 10443) set for this request, then the external port scanner will show that port 10443 is open on FortiGate.
Run nmap (external port scanner) on the WAN interface of FortiGate. It will show port 10443 as open:
Note: This port cannot be disabled on the FortiGate even if the web mode is disabled, since the FortiGate is set to listen for traffic requests coming from Tunnel mode (FortiClient) on this particular port.
There is no way to completely disable this listening port. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.