Description
This article explains how fixed port can be set on firewall policy, and some of the reasons this change is needed.
Scope
FortiGate.
Solution
A TCP/IP connection is identified by a four-element tuple:
To establish a TCP/IP connection only a destination IP and port number are needed, the operating system automatically selects the source IP and port when NAT (SNAT) is performed. NAT translates source ports to keep track of connections for a particular service.
Some network configurations do not operate correctly if a NAT policy translates the source port of packets used by the connection.
This is caused by the different source ports in the IP header (changed by NAT) and the source port communicated in the payload.
Most common cases:
config firewall policy
edit <ID>
set fixedport enable
end
However, enabling fixed port means that only one connection can be supported through the firewall for this service. This is expected for the local PBX that connects only to the SIP provider.
To verify the fixed port or preserve the source port on IP-Pool:
diag firewall ippool list
Related articles:
Technical Tip: Using 'set fixedport enable' in a policy with 'fixed-port-range' type ippool
Technical Tip: How to preserve source port when central NAT is enabled
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.