Hi, relatively new to the world of PCI compliance as well as certificates and need some advice. A PCI scan continues to fail with the certificate connected with port 8013 being the issue. I cannot for the life of me find the service that runs on that port to either shut it off or correct the certificate issue. Any help is greatly appreciated.
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi mikeymouse,
The ports used by FortiOS can be found in the documentation site here:-
https://docs.fortinet.com/document/fortigate/7.0.0/fortios-ports/637075/incoming-ports
It lists port 8013 as being used by FortiClient for "Compliance and Security Fabric".
If you aren't using FortiClient (and dont plan to) then you should be able to turn this off via change to the "local in" policy.
Again, there is some guidance on the documentation site here:-
https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/363127/local-in-policies
I hope that's enough to help you resolve your issues!
Kind Regards,
Andy.
Hi mikeymouse,
The ports used by FortiOS can be found in the documentation site here:-
https://docs.fortinet.com/document/fortigate/7.0.0/fortios-ports/637075/incoming-ports
It lists port 8013 as being used by FortiClient for "Compliance and Security Fabric".
If you aren't using FortiClient (and dont plan to) then you should be able to turn this off via change to the "local in" policy.
Again, there is some guidance on the documentation site here:-
https://docs.fortinet.com/document/fortigate/7.0.3/administration-guide/363127/local-in-policies
I hope that's enough to help you resolve your issues!
Kind Regards,
Andy.
To elaborate on Andrew's response, if you don't use FortiClient or FortiAP, you can disable (depending on your FortiGate firmware version) either disable FortiTelemetry or Security Fabric (which is FortiTelemetry and CAPWAP bundled) on the interface(s). If you do use FortiAPs for wireless stuff, and only have the Security Fabric option, you can't disable it. In that case a local-in policy as Andrew advised is your best option.
Cheers!
Thanks, the local in policy solved my issue then. I appreciate the responses!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.