Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Knuppel1983
New Contributor

IPsec TCP port per tunnel

I have 3 vpn connections:

1. Azure - mainsite FG (ipsec)

2. branchsite FG - mainsite FG (ipsec)

3. clients - mainsite FG (ssl-vpn)


With the new ike-port option is should be possible to move to ip-sec over port 443.

config system settings
set ike-port 443
end

 

This sets the port globally though. I can get around this for tunnels 2 and 3, but Azure site-to-site VPN does not have an option to change port (or use tcp). Is it possible to change the port per tunnel? If not, is this on the roadmap?

12 REPLIES 12
sw2090
SuperUser
SuperUser

I gues in this case you cannot blame fortinet. POrt 500 and 4500 are IPSec standard defined in rfc #7296. So it is the other side that doesn't support the standards. And M$ keeps it with the words of Adam Savage: "I reject your reality and substitute my own!" :)

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
sw2090
SuperUser
SuperUser

Oh m$ does support the defaults?! How did that happen xD

Well it is correct that you cannot change them because they are stadardized (as said defined in rfc #7296). So to support as much IPSec as possible you usually do not allow to chang them.

But if they do then I don't understand whay you need to change that?

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Knuppel1983

Haha. Not putting blame anywhere, just want a working solution.

Can anyone else test if TCP and UDP IPSec tunnels can co-exist?
For reference: https://infosecmonkey.com/tcp-encpsulation-of-esp-packets-for-vpn-tunnels/

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors