Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Drax658
New Contributor

Fortigate negotiating on port 853 despite DNS over TLS is disabled

Hello,

 

We have implemented a vulnerability scanner in our organization, which has detected, among other things, that our FortiGates are listening on port 853 and are presenting themselves with a certificate, which is called "Fortinet_Factory" in the Fortigate web UI. Could you tell me if it is normal that this port is open despite the fact that DLS over TLS is disabled on the device? What other service could be listening on this port? The policy of my organization is to remove all vulnerabilities, so a vulnerability related to the fact that a certificate is not recognized or that a negation has occurred using a set of ciphers considered by the scanner as insecure must be eliminated. Thank you in advance for your help

3 REPLIES 3
adambomb1219
SuperUser
SuperUser

Is the FortiGate running as a DNS server?

Drax658

Yes, it is running as a primary DNS server for all devices in my organizations.

sw2090
SuperUser
SuperUser

if you have apple devices behind your FGT and use the FGT as DNS you will need DSL over TLS :)

If not you could disable it in the DNS Settings.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors