Hi
Fortigate 60F, blocked after upgrade to release 7.4.9.
i can't access via https. Can someone help me to troubleshoot it?
Message:
Secure Connection Failed
An error occurred during a connection to 172.16.1.1:11443. PR_CONNECT_RESET_ERROR
Error code: PR_CONNECT_RESET_ERROR
Update:
if i change admin-sport it works!
But port 11443, is default password used any service?
Hi @marconet-22
You can check the TCP port using 11443
dia sys tcpsock | grep ike
YOu can check some documents:
Incoming ports | FortiGate / FortiOS 7.6.0 | Fortinet Document Library
Bill
Hi Bill
this is the output of diag sys tctpsock | grep 11443
ike-TCP-port:
config system settings
set h323-direct-model enable
set gui-local-in-policy enable
set gui-dynamic-routing enable
set gui-sslvpn enable
set ike-tcp-port 31443
end
Hi @marconet-22
when you set ike-tcp-port 31443, it should not conflict with ike port 11443.
So the GUI should be okay.
Thanks
Bill
Created on 10-22-2025 01:39 AM Edited on 10-22-2025 01:41 AM
Fortiget support assist me and write me that port 11443 is a port that ike daemon is in listening instead ike-tcp port. I haven't fortigate in release 7.6. Can someone test it?, if port 11443 is used about it?
Hi,
Could you please confirm from which previous firmware version you upgraded to 7.4.9? Please verify if port conflict between TCP 443 and the IKE TCP port. Starting from FortiOS version 7.4.2, a proprietary solution was introduced to enable the encapsulation of Encapsulating Security Payload (ESP) packets within TCP headers, and this allows ESP packets to use a specific TCP port.
Please refer to the document below for more information.
Hi
upgrade from 7.4.8 to 7.4.9 and ike tcp port doesn't in conflict with gui https port.
it means some new port has been introduced in version 7.4.9 which is conflicting.
You can verify the services listening by using command "diag sys tcpsock"
| User | Count |
|---|---|
| 2719 | |
| 1416 | |
| 810 | |
| 738 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.