Hello. When I do Nmap scan to my wan ip address, all ports appear open. There is no port forwarding in the vip section. In the Dos Policy section, threshold values are entered 10 for TCP and udp. Also all services are deny in local in Policy section. What could be the reason why the ports appear open in nmap?
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
It cannot be, if Local-in policy has deny everything, which means most probably you have something misconfigured. Look at show firewall vip, show firewall local-in and also logs of Fortigate - do you see your nmap scan hitting the firewall?
User | Count |
---|---|
2530 | |
1350 | |
795 | |
639 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.