Description | This article describes how to resolve or troubleshoot misclassification of RDP traffic as MMS. |
Scope | FortiGate. |
Solution |
RDP typically operates over TCP port 3389, but it also supports UDP port 3389. When UDP is used, RDP traffic can inadvertently match the default MMS service definition if that service is configured with a wide UDP port range that includes 3389.
In this setup:
As a result, when RDP uses UDP 3389, it is matched against the MMS service, causing incorrect classification in the logs and potential traffic handling issues.
To resolve the misclassification issue, remove the UDP port range from the MMS service definition if it is not required or narrow it down to exclude port 3389.
For example:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.