Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kavi_Wi-FI
New Contributor

FortiGate to FortiAnalyzer: OFTP protocol

As per my understanding FGT & FAZ  uses TCP port 514 & UDP 514 in log communication. 

 

TCP port 514 used in RSH protocol to execute remote shell commands in FGT to get information also it is not secured compared to SSH protocol. so to understand how Fortinet securing the communication over internet using this protocol ?

 

  1. What is the recommended setup to establish a communication between FGT & FAZ? Whether it is over internet or using only SD-WAN?
  2. If FAZ using both TCP/UDP 514 (OFTP & Log communication streams) to communicate with FGT then will it form TLS/DTLS connectivity between FortiGate & FortiAnalyzer?
  3. TCP 514 is for Remote Shell (RSH)protocol & it is not secure communication, so what is the difference in using this same TCP 514 port in Fortinet and how it is secure over internet?
  4. What is the difference in RSH & OFTP protocol in Fortinet? Since TCP 514 is used for RSH then why Fortinet mentioning this is OFTP?
  5. If we enable reliable option in FGT then both log and OFTP communication use TCP 514? Is this recommended to enable always?
  6. What information is sending through OFTP protocol? Since we have a log communication stream to send logs to FGT.
  7. As per my understanding,  between FGT & FAZ it is using both RSH and SSH protocol to fetch information.
  1. When FGT & FAZ in same LAN/network it is using SSH
  2. When FGT & FAZ not in same LAN then using RSH
  3. How FAZ is deciding to use RSH & SSH to contact FGT

 

4 REPLIES 4
Anthony_E
Community Manager
Community Manager

Hello Kavi,

 

Hope you are doing well :).

 

Same as before:

 

I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.

 

Regards,

Anthony-Fortinet Community Team.
Anthony_E
Community Manager
Community Manager

I have finally found this document:

 

https://docs.fortinet.com/document/fortigate/6.4.0/ports-and-protocols/109281/oftp-optimized-fabric-...

 

Could you please tell me if it helps?

 

Regards,

Anthony-Fortinet Community Team.
Kavi_Wi-FI

I already gone though this docs but not helpful to get the answers for my queries.

 

if anyone tested with pcap then they can see all the packets I mentioned above.

 

anyone having any idea to get the answers for all the queries?

gxu16_FTNT
Staff
Staff

wireshark parse traffic protocol based on port number by default, port 514 is well known port for syslog so it parses as RSH. You shall manually decoded it as TLS.

Labels
Top Kudoed Authors