Created on
08-28-2025
10:57 PM
Edited on
09-08-2025
01:30 AM
By
Anthony_E
Description | This article describes ports' behavior in IKE negotiation, IPsec/IKE Negotiation Ports (with and without NAT-Traversal). |
Scope | FortiGate. |
Solution |
Ports Used in IKE/IPsec.
From that point onward, all VPN traffic (IKE + ESP) uses UDP/4500.
Always start on UDP/500 due:
All IKE negotiations must begin on UDP/500 for compatibility. A peer cannot know in advance if NAT exists.
After detection, all further packets (IKE and ESP) are encapsulated in UDP/4500.
Port Summary.
The reason to always see the first attempt on UDP/500 (even with NAT-T) is that the IKE standard requires negotiation to begin there.
Related articles: Technical Tip: IPSec VPN NAT-traversal Troubleshooting Tip: IPsec VPN tunnels Troubleshooting Tip: IPsec VPN failure due to one way IKE (UDP 500) communication |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.