Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
salassilvaj
New Contributor III

SDWAN TCP-UDP ports fort ipsec tunnel used behind nat

Does someone know which ports are used for vpn ipsec tunnel under sdwan scenario considering this fortigate is behind a NAT ISP connection? apart from UDP 4500 and 500 ports which one are require to allow it.

Jonathan Salas
Jonathan Salas
3 REPLIES 3
AEK
SuperUser
SuperUser

Yes, only UDP 500 and 4500 are used.

Starting from 7.4.1 you can customize it on TCP.

https://docs.fortinet.com/document/forticlient/7.4.0/new-features/914884/ipsec-vpn-over-tcp-7-4-1

AEK
AEK
salassilvaj
New Contributor III

for ssl vpn dial up connection are same ports? ISP firewall must allow only these ports ? or only the ports assigned through the forti config

Jonathan Salas
Jonathan Salas
AEK

SSL VPN port is 443 or 10443 (usually default values).

For SSL VPN security it is recommended to change it to a high non standard port.

The ISP firewall must allow the port numbers you have configured for IPsec and SSL VPN if you want them to be reachable.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors