Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ssan239
New Contributor III

Port Scan showing port 541 being open on FortiGate WAN interface

Hi Team,

Though we disabled FMG-Access in the administrative access we see the port scan is showing 541 opened on WAN interface.

I followed the below article.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Port-Scan-showing-port-541-being-open-on-F...

I used the command and found that the port is still listening on 541. Please let us know what would be the reason for this, even after disabling we still see it is listening. Is it normal or this needs to be checked?

 

Regards,

Sanjay S

3 REPLIES 3
hbac
Staff
Staff

Hi @ssan239,

 

TCP/541 is also used for FortiGuard connection. Please refer to https://docs.fortinet.com/document/fortigate/6.4.0/hardening-your-fortigate/529217/fortios-ports-and...

 

Regards, 

ssan239
New Contributor III

Hi Hbac,

Thanks for the response. I dont think we use Fortiguard, even in licenses i dont see any specific option called Fortiguard Services. In licenses i can only see Forti Support, Firmware and Updates, IPS, AV and Web Filtering. Does it mean Fortiguard enabled?

 

aahmadbasri
Staff
Staff

Hi @ssan239,

 

Port 541 is generally used for management.
Is central-management configured on the device ?
# get system central-management

 

Regards, 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors