Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
shane_85
New Contributor

ALL vs Specified port

Hi All,

I have a 300D firewall,  came across something i think is strange hopefully you lot can shed some light on it.

in a nutshell my policy  looks like this

Internal > External from any source adress to destination FQDNsometing.com | schedule always | services TCP-51460 allow/accept ........ if i go to my browser and type in the URL somthing.com:51460.....nothing happens , if i run a sniffer in the external interface no packets for that port ,

 

as soon as i change the services to all instead or TCP-51460 it works and the sniffers sees packets (obviously) please let me know what you think is wrong ?

 

Shane

2 Solutions
emnoc
Esteemed Contributor III

You should really use diag debug flow and validate the policy-id trhat's being matched. I would then re-order the fwpolicy ID sequences  to ensure the policy with the custom policy is being matched.

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
Dave_Hall
Honored Contributor

I am guessing you may be messing up on setting up the custom port service.  Make sure you are setting the source port range 0 (1) to 65535; dest port should be 51460.  If I had to do this, it may be similar to the following (on 5.0.x)...

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

View solution in original post

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
3 REPLIES 3
emnoc
Esteemed Contributor III

You should really use diag debug flow and validate the policy-id trhat's being matched. I would then re-order the fwpolicy ID sequences  to ensure the policy with the custom policy is being matched.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Dave_Hall
Honored Contributor

I am guessing you may be messing up on setting up the custom port service.  Make sure you are setting the source port range 0 (1) to 65535; dest port should be 51460.  If I had to do this, it may be similar to the following (on 5.0.x)...

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
shane_85

thank you guys this has been solved, yup I didn't have the source port extended all the way up to 65535 :) just had to set to one.

Labels
Top Kudoed Authors