FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ap
Staff
Staff
Article Id 336084
Description

This article describes how to restrict traffic using a firewall policy when there is a need to allow traffic from only a specific source port or source port range for a specific service.

Scope FortiGate.
Solution

This article has restricted RDP communication to specific source port ranges 1000 to 20000 for example.

  • It is necessary to restrict the source port/source port range within the existing service/by creating a new custom service. It is recommended to create a new custom service instead of changing source port information within the default available services
  • It has been created an 'RDP-restricted' custom service by following Policy & Objects -> Services -> Create New:

 

pic7.PNG

 

  • Select the Protocol Type and Specify the destination port as required. It has been specified TCP protocol and destination port 3389 for RDP. It is possible to specify this same port number in the Low and High boxes if it is a single port. If it is a range of ports, it is possible to specify lower and upper numbers of range accordingly.
     

pic1.PNG

 

 

  • After that, it is possible to enable the 'Specify Source Ports' switch and specify the lower and upper range of ports.

pic2.PNG

 

pic3.PNG

 

  • Once it is configured, it is possible to hover over the newly configured service 'RDP-restricted' and confirm that the source port range is changed to 1000-20000.

 

pic6.png

 

Contributors