Good morning all,
I'm having trouble opening port 7450 and another port,
There are some that open that work fine but for ports 7450 and 20080 it refuses to open them even though I did the same for the ports that are open. I don't understand why it doesn't work.
What I did was a virtual IP address with my public IP address on my targeted local IP address and opened port 7450 and created a rule for that as well.
But when I go on tools to check port 7450 it is close
Thank you for your answers.
Does the destination IP live on the FGT? If not, it might be closed on the server/destination side.
Hi, I'm sorry but what is FGT because the acronym in English is hard because I'm French I'm sorryv
I meant FortiGate. Some just use FG.
Yes I use FG but 7450 and 20080 are not open
Then again, is it out-to-in or in-to-out? And the destination IP is outside of the FGT?
it is incoming and outgoing call and the outgoing call points to an IP address outside the FTG
So this is for your phone system connected to a service provider on the Internet.
Did you configured a VIP for out-to-in traffic so the provider reaches the outside/public IP at the FGT then mapped to the server's local/private IP? I'm assuming you scanned the public IP from the Internet and found those ports closed, right? Then please share the vip config via CLI after masking public IP(s).
Then, as long as the policy that has this vip applied is allowing TCP 7450 and 20080 toward the interface the phone system is connected, and as long as the system is listening to the ports, those ports should show up as open when you scan the wan2's IP.
I would look at the phone system side. But to prove the FGT is passing the scan packets for those ports, you can sniff the inside port with 'host 192.168.0.178' while scan is happening. You should see them passing through.
If you can't see them, now you have to run "flow debug" to see why the FGT is dropping. You can find "how to" by simply putting "fortigate flow debug" in an internet search. You need to set filter with those ports.
If you're not comfortable doing it or don't have time, just open a ticket and get help from TAC.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.