I have 3 vpn connections:
1. Azure - mainsite FG (ipsec)
2. branchsite FG - mainsite FG (ipsec)
3. clients - mainsite FG (ssl-vpn)
With the new ike-port option is should be possible to move to ip-sec over port 443.
config system settings
set ike-port 443
end
This sets the port globally though. I can get around this for tunnels 2 and 3, but Azure site-to-site VPN does not have an option to change port (or use tcp). Is it possible to change the port per tunnel? If not, is this on the roadmap?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I gues in this case you cannot blame fortinet. POrt 500 and 4500 are IPSec standard defined in rfc #7296. So it is the other side that doesn't support the standards. And M$ keeps it with the words of Adam Savage: "I reject your reality and substitute my own!" :)
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Oh m$ does support the defaults?! How did that happen xD
Well it is correct that you cannot change them because they are stadardized (as said defined in rfc #7296). So to support as much IPSec as possible you usually do not allow to chang them.
But if they do then I don't understand whay you need to change that?
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Haha. Not putting blame anywhere, just want a working solution.
Can anyone else test if TCP and UDP IPSec tunnels can co-exist?
For reference: https://infosecmonkey.com/tcp-encpsulation-of-esp-packets-for-vpn-tunnels/
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.