Hi all
I am trying to setup ipsec dialup (IKEv2) using port tcp/443 on a FGT200G with 7.4.8 and with Forticlient (vpn only version) 7.4.3.
Amongst other issues, I am facing a connection block (not negotiation error, I seem not to get that far).
My connections requests from my client (and from my IP) are seen on the fortigate (on port tcp/443) as expected, but are being blocked by local-in-policy number 0.
I have added one single local-in-policy that should allow ssh, icmp and https (which is tcp/443 in the service object) from my IP address.
ICMP works and the FGT replies for my IP, however, tcp/443 is being blocked,
As this is all in one single local-in-policy, I have no idea where I went wrong - ICMP works, so why doesn't tcp/443?
Thanks for giving me a hint where to look
Best regards
A couple of things you can try.
1. temporarily remove/disable all local-in-policy for test purpose. You probably need to do that in a maintenance window.
2. change the port from 443 to something else like 11443.
If either of them doesn't work, something else is causing it.
Toshi
User | Count |
---|---|
2640 | |
1401 | |
810 | |
686 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.