We have a FortiEMS 7.4 and we want to expose RPC ports through the ZTNA.
For what I have read so far there is only possibility to define single port per ZTNA destination rule.
The problem is that by specification RPC uses:
- TCP 135
- Dynamic TCP range 49152-65535.
How to make the dynamic range accessible through the ZTNA?
On the FortiGate site it is OK, but on the client site when we try to create destination rule like:
Server: 49152-65535
The server is no longer resolved through ZTNA and no connection can be processed by it.
you can try doing a TCP forwarding instead of https.
You can refer the article referred and instead of youtube.com use your destination server IP with no port forward,
I am doing TCP forwarding.
But for use of dynamic ports I need to define 14K rules, which is 11MB policy and is not working.
It is easy to forward one port, I need a huge range of ports.
User | Count |
---|---|
2428 | |
1303 | |
778 | |
557 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.