Does someone know which ports are used for vpn ipsec tunnel under sdwan scenario considering this fortigate is behind a NAT ISP connection? apart from UDP 4500 and 500 ports which one are require to allow it.
Yes, only UDP 500 and 4500 are used.
Starting from 7.4.1 you can customize it on TCP.
https://docs.fortinet.com/document/forticlient/7.4.0/new-features/914884/ipsec-vpn-over-tcp-7-4-1
for ssl vpn dial up connection are same ports? ISP firewall must allow only these ports ? or only the ports assigned through the forti config
SSL VPN port is 443 or 10443 (usually default values).
For SSL VPN security it is recommended to change it to a high non standard port.
The ISP firewall must allow the port numbers you have configured for IPsec and SSL VPN if you want them to be reachable.
User | Count |
---|---|
2567 | |
1358 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.