Hi All,
I have a 300D firewall, came across something i think is strange hopefully you lot can shed some light on it.
in a nutshell my policy looks like this
Internal > External from any source adress to destination FQDNsometing.com | schedule always | services TCP-51460 allow/accept ........ if i go to my browser and type in the URL somthing.com:51460.....nothing happens , if i run a sniffer in the external interface no packets for that port ,
as soon as i change the services to all instead or TCP-51460 it works and the sniffers sees packets (obviously) please let me know what you think is wrong ?
Shane
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You should really use diag debug flow and validate the policy-id trhat's being matched. I would then re-order the fwpolicy ID sequences to ensure the policy with the custom policy is being matched.
PCNSE
NSE
StrongSwan
I am guessing you may be messing up on setting up the custom port service. Make sure you are setting the source port range 0 (1) to 65535; dest port should be 51460. If I had to do this, it may be similar to the following (on 5.0.x)...
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
You should really use diag debug flow and validate the policy-id trhat's being matched. I would then re-order the fwpolicy ID sequences to ensure the policy with the custom policy is being matched.
PCNSE
NSE
StrongSwan
I am guessing you may be messing up on setting up the custom port service. Make sure you are setting the source port range 0 (1) to 65535; dest port should be 51460. If I had to do this, it may be similar to the following (on 5.0.x)...
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
thank you guys this has been solved, yup I didn't have the source port extended all the way up to 65535 :) just had to set to one.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.