Hello to all.
We have a Fortigate with a managed FortiAP
But now, we see a lot of traffic from the Interface asigned to the fortiAp to the last IP of the blok and port udp/6096, we check all te know common ports in the version 6.4 but no found any information.
This is an example,
FROM TO PROTO LENGTH SRC PORT DST PORT
10.10.10.1 10.10.10.255 UDP 87 20530 → 6096 Len=45
We run a packet capture and open in wireshark, but can't see some relevant.
Can somebody tell me some about this issue?
Thnks to all!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The last IP of the subnet means that this is a broadcast traffic. Do you know if the CAPWAP port is changed in this setup?
You can run this command to check the configuration of the AP:
# cfg -s
Hello @ebilcari Emirjon, the config for the AP i'ts deploy from the Fortigate as usual, not local config, and yes i'ts like broadcast but in another port like never seen before. This comand "cfg -s" i'ts on the FortiAP directly? on the Fortigate i'ts unknown.
This is the config on the VAP
edit "Wlan_01"
set vdom "01"
set fast-roaming enable
set external-fast-roaming disable
set mesh-backhaul disable
set max-clients 10
set ssid "WLan"
set broadcast-ssid enable
set security wpa2-only-personal
set pmf disable
set voice-enterprise disable
set fast-bss-transition disable
set eapol-key-retries enable
set radius-mac-auth disable
set encrypt AES
set local-standalone disable
set local-bridging disable
set intra-vap-privacy enable
set schedule "Office"
set ldpc rxtx
set mpsk disable
set split-tunneling disable
set vlanid 0
set multicast-rate 0
set multicast-enhance disable
set broadcast-suppression dhcp-up dhcp-down dhcp-starvation arp-known arp-unknown arp-reply arp-poison arp-proxy netbios-ns netbios-ds ipv6 all-other-mc all-other-bc
set me-disable-thresh 32
set probe-resp-suppression disable
set radio-sensitivity disable
set quarantine enable
set vlan-pooling disable
set dhcp-option82-insertion disable
set gtk-rekey disable
set qos-profile ''
unset rates-11a
unset rates-11bg
unset rates-11n-ss12
unset rates-11n-ss34
unset rates-11ac-ss12
unset rates-11ac-ss34
set passphrase ENC .....
next
Where can i run the comand #"cfg -s"
Thnks for all Emirjon
This is the output for the command cfg -s
BAUD_RATE:=9600
LOGIN_PASSWD_ENC:=
ADMIN_TIMEOUT:=5
WANLAN_MODE:=WAN-ONLY
ADDR_MODE:=DHCP
AP_IPADDR:=192.168.1.2
AP_NETMASK:=255.255.255.0
IPGW:=192.168.1.1
AP_MODE:=0
DNS_SERVER:=208.91.112.53
STP_MODE:=0
AP_MGMT_VLAN_ID:=0
ALLOW_TELNET:=2
ALLOW_HTTP:=2
ALLOW_HTTPS:=2
ALLOW_SSH:=2
DDNS_ENABLE:=0
AC_DISCOVERY_TYPE:=0
AC_IPADDR_1:=192.168.1.1
AC_IPADDR_2:=
AC_IPADDR_3:=
AC_HOSTNAME_1:=_capwap-control._udp.example.com
AC_HOSTNAME_2:=
AC_HOSTNAME_3:=
AC_DISCOVERY_MC_ADDR:=224.0.1.140
AC_DISCOVERY_DHCP_OPTION_CODE:=138
AC_DISCOVERY_FCLD_APCTRL:=
AC_DISCOVERY_FCLD_ID:=
AC_DISCOVERY_FCLD_PASSWD_ENC:=
AC_CTL_PORT:=5246
AP_DATA_CHAN_SEC:=clear,ipsec,dtls
MESH_AP_TYPE:=0
MESH_MAX_HOPS:=4
MESH_SCORE_HOP_WEIGHT:=50
MESH_SCORE_CHAN_WEIGHT:=1
MESH_SCORE_RATE_WEIGHT:=1
MESH_SCORE_BAND_WEIGHT:=100
MESH_SCORE_RSSI_WEIGHT:=100
LED_STATE:=2
It's possible to list the connections like ss or netstat in the CLI of the FortiAp? If i can see the traffic, can match the PID associate and know what feature are using this, i just think
I'm not aware that such command exist in the AP. I guess this may be some dynamic port but I can't think about its service. What is the pattern of this broadcast traffic and is it always using the same port 6096?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.