Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MaAtVA
New Contributor

Port scan/test from Fortigate

Hello, may i am doing something wrong or this is complete wrong here since i cannot find any post about my question.

I am maintaining several fortigate firewalls without having devices which are placed behind the firewalls. When i get troubleshooting tickets it would be fine for me to have a possibility to check if a port on a remote device is open/accessable or it is not because for example it is blocked by a local firewall on the device.

I know the "exec telnet" command, but for me it is only a workaround since depending on the daemon listing on the remote port telnet keeps connections established without the possibility to cancel them (for ex. with CTRL-c), port 445 SMB is such a candidate.

I am a little bit supriesed that no one seams to have the use case for a port scanner / port test tool on Fortigates. Is there a command line tool on Fortigates to test remote ports and i have no idea of them or how do you deal with such situations? Creating temporary rules is also no option since the Fortigates are behind other Firewalls which would block port tests started on my local computer.

I'm eager to hear how you are dealing with such situations.

2 REPLIES 2
funkylicious
SuperUser
SuperUser

hi,

like you mentioned, a first test would be to telnet from the FGT to the remote device on that port, but this will be limited to TCP ports.

also, this test would be sometimes successful as the source interface/ip would be a local IP if the destination device is locally connected, but a remote one would fail due to a local firewall ( sometimes ).

a second test would be to do a policy match and see if there is a firewall rule that would allow the traffic on that FGT then move with the investigation further.

another test would be to a do a session with the user that claims the issue and see if the traffic reaches the FGT and what happens with it ( like sniffer or debug flow ).

 

a port scanner utility/functionality on the FGT would not have a real impact in my opinion and the ones from above would be the most accurate.

"jack of all trades, master of none"
"jack of all trades, master of none"
MaAtVA

This is not what i wanted to hear but what i expected. I know the possibilities you wrote but i also look forward to a fortigate command allowing port tests, because i still believe it would help me and also others.
For me this is a tool that is a must have on every firewall, but this view does not have to be shared ;)

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors