Hi!
I have a Fortigate-50B (system 4.0 MR3) model, and I have to open ports like 8080, 993,465 because these ports are not listed at "Predefined" into "Services". All this traffic is being blocked by the firewall.
I tried to create port 8080 into "Custom", by defining the source and destination port low/high with 8080, but after I placing in a Policy nothing changes and the port continue to be blocked.
What should I do for make this simple task?
Thank you.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Attached (top part) is a custom service (based on your requirements); (bottom part) is just a service group (on 5.0.9) grouping all the email services. (These are just examples.) Remember when you define your firewall policy -- move the rule up in the firewall chain so it get's executed.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
It would help if you can define what you are trying to accomplish by opening these ports. Are you trying to allow traffic on those ports out (internal->WAN) or outside in (WAN->Internal).
In a custom service, you generally define the dest/target (TCP/UDP) ports you want open -- the source or originating ports you (edit: usually) leave at 1-65535.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
The traffic is Internal->WAN
Attached (top part) is a custom service (based on your requirements); (bottom part) is just a service group (on 5.0.9) grouping all the email services. (These are just examples.) Remember when you define your firewall policy -- move the rule up in the firewall chain so it get's executed.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Ok Dave,
I made the same way as you said and worked perfectly!
Thank you!
Hi Team, Please help on the below.
I am looking for Policy create and NAT and Port Opening.
I have public IP 197.156.Y.Y and Private IP 172.16.x.x. (Video conference codec server).
172.16.X.X---static Nat to ---197.156.Y.Y
And The port should open as below table.
FunctionPort Rangepoint to point call+ People&Content Gatekeeper Discovery (RAS)1718-1719 UDPQ.931 Call Setup1720 TCPAudio Call Control1731 TCPVideo Range3230-3253 TCP/UDPAudio Range3230-3253 TCP/UDPData/FECC Range3230-3253 TCP/UDPPort Range 1718-1719 UDP1720 TCP1731 TCP3230-3253 TCP/UDP3230-3253 TCP/UDP3230-3253 TCP/UDPmy advice: use a port-less (full) VIP and use a service group on the incoming policy. Much less effort than a dozen of VIPs and one VIP group.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.