Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kevin_Noble
New Contributor

NMAP Penetration Testing

I was just trying an NMAP scan (using the free Network Security Toolkit running from a CD) against the IP address on my external interface on a couple of our Fortinet boxes with fairly recent firmware. NMAP shows 10 ports are open including 443/tcp, 21/tcp, 25/tcp, 80/tcp, 443/tcp, 110/tcp, 5190/tcp, 119/tcp and 5050/tcp - this was by doing a SYN stealth scan with NMAP. Does anybody know why there are 10 ports open? Even with no inbound rule at all and ping disabled and all external interface administrative ports turned off these ports show up as open and if you manually ftp to the external port, it does connect so FTP is kind of open - again does anybody know why? Can somebody else try this on their Fortinet boxes and let me know what you see?
2 REPLIES 2
rwpatterson
Valued Contributor III

Are you sure you have the correct addresses? I just tried to FTP to 8 of mine, and they all failed... Running a comprehensive scan now. Hopefully, the FGT will drop ' em all...

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Kevin_Noble
New Contributor

It must have been something strange with the originating source connection or route I was taking - I tried it from a second outside connection and it scanned as expected.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors