Hello,
We have implemented a vulnerability scanner in our organization, which has detected, among other things, that our FortiGates are listening on port 853 and are presenting themselves with a certificate, which is called "Fortinet_Factory" in the Fortigate web UI. Could you tell me if it is normal that this port is open despite the fact that DLS over TLS is disabled on the device? What other service could be listening on this port? The policy of my organization is to remove all vulnerabilities, so a vulnerability related to the fact that a certificate is not recognized or that a negation has occurred using a set of ciphers considered by the scanner as insecure must be eliminated. Thank you in advance for your help
Is the FortiGate running as a DNS server?
Yes, it is running as a primary DNS server for all devices in my organizations.
if you have apple devices behind your FGT and use the FGT as DNS you will need DSL over TLS :)
If not you could disable it in the DNS Settings.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
User | Count |
---|---|
2331 | |
1262 | |
772 | |
453 | |
438 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.