Description | This article describes why a SYN-ACK is seen from FortiGate when nmap is initiated toward a non-existing IP address. |
Scope | FortiGate. |
Solution |
When nmap is initiated towards a non existing IP address on both ports 5060 and port 2000, a SYN-ACK is observed on FortiGate. This an expected behavior when the ALG configuration is set to a proxy-based mode.
If the VoIP algorithm is changed to kernel-helper-based, SYNC-ACK will not be observed on FortiGate
config system settings set default-voip-alg-mode proxy-based * | kernel-helper-based end
Related articles: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.