Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dachrixkross
New Contributor II

Rare UDP Traffic

Hello to all.

 

We have a Fortigate with a managed FortiAP

But now, we see a lot of traffic from the Interface asigned to the fortiAp to the last IP of the blok and port udp/6096, we check all te know common ports in the version 6.4 but no found any information.

 

This is an example,

     FROM             TO             PROTO    LENGTH    SRC PORT   DST PORT

  10.10.10.1   10.10.10.255    UDP          87           20530 →       6096 Len=45

 

We run a packet capture and open in wireshark, but can't see some relevant.

 

Can somebody tell me some about this issue?

 

Thnks to all!

 

6 REPLIES 6
ebilcari
Staff
Staff

The last IP of the subnet means that this is a broadcast traffic. Do you know if the CAPWAP port is changed in this setup?
You can run this command to check the configuration of the AP:

# cfg -s

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Dachrixkross

Hello @ebilcari Emirjon, the config for the AP i'ts deploy from the Fortigate as usual, not local config, and yes i'ts like broadcast but in another port like never seen before. This comand "cfg -s" i'ts on the FortiAP directly? on the Fortigate i'ts unknown.

This is the config on the VAP

edit "Wlan_01"

set vdom "01"

set fast-roaming enable

set external-fast-roaming disable

set mesh-backhaul disable

set max-clients 10

set ssid "WLan"

set broadcast-ssid enable

set security wpa2-only-personal

set pmf disable

set voice-enterprise disable

set fast-bss-transition disable

set eapol-key-retries enable

set radius-mac-auth disable

set encrypt AES

set local-standalone disable

set local-bridging disable

set intra-vap-privacy enable

set schedule "Office"

set ldpc rxtx

set mpsk disable

set split-tunneling disable

set vlanid 0

set multicast-rate 0

set multicast-enhance disable

set broadcast-suppression dhcp-up dhcp-down dhcp-starvation arp-known arp-unknown arp-reply arp-poison arp-proxy netbios-ns netbios-ds ipv6 all-other-mc all-other-bc

set me-disable-thresh 32

set probe-resp-suppression disable

set radio-sensitivity disable

set quarantine enable

set vlan-pooling disable

set dhcp-option82-insertion disable

set gtk-rekey disable

set qos-profile ''

unset rates-11a

unset rates-11bg

unset rates-11n-ss12

unset rates-11n-ss34

unset rates-11ac-ss12

unset rates-11ac-ss34

set passphrase ENC .....

next

 

Where can i run the comand  #"cfg -s"

Thnks for all Emirjon

Dachrixkross

This is the output for the command cfg -s

 

BAUD_RATE:=9600

LOGIN_PASSWD_ENC:=

ADMIN_TIMEOUT:=5

WANLAN_MODE:=WAN-ONLY

ADDR_MODE:=DHCP

AP_IPADDR:=192.168.1.2

AP_NETMASK:=255.255.255.0

IPGW:=192.168.1.1

AP_MODE:=0

DNS_SERVER:=208.91.112.53

STP_MODE:=0

AP_MGMT_VLAN_ID:=0

ALLOW_TELNET:=2

ALLOW_HTTP:=2

ALLOW_HTTPS:=2

ALLOW_SSH:=2

DDNS_ENABLE:=0

AC_DISCOVERY_TYPE:=0

AC_IPADDR_1:=192.168.1.1

AC_IPADDR_2:=

AC_IPADDR_3:=

AC_HOSTNAME_1:=_capwap-control._udp.example.com

AC_HOSTNAME_2:=

AC_HOSTNAME_3:=

AC_DISCOVERY_MC_ADDR:=224.0.1.140

AC_DISCOVERY_DHCP_OPTION_CODE:=138

AC_DISCOVERY_FCLD_APCTRL:=

AC_DISCOVERY_FCLD_ID:=

AC_DISCOVERY_FCLD_PASSWD_ENC:=

AC_CTL_PORT:=5246

AP_DATA_CHAN_SEC:=clear,ipsec,dtls

MESH_AP_TYPE:=0

MESH_MAX_HOPS:=4

MESH_SCORE_HOP_WEIGHT:=50

MESH_SCORE_CHAN_WEIGHT:=1

MESH_SCORE_RATE_WEIGHT:=1

MESH_SCORE_BAND_WEIGHT:=100

MESH_SCORE_RSSI_WEIGHT:=100

LED_STATE:=2

Dachrixkross

It's possible to list the connections like ss or netstat in the CLI of the FortiAp? If i can see the traffic, can match the PID associate and know what feature are using this, i just think

ebilcari

I'm not aware that such command exist in the AP. I guess this may be some dynamic port but I can't think about its service. What is the pattern of this broadcast traffic and is it always using the same port 6096?

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Dachrixkross
New Contributor II

Labels
Top Kudoed Authors