Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

UDP port 8888 denied on Fortigate

Hello. I just installed the endpoint Forticlient with Antivirus and Antispam. All of my user are behind a idenity based Fortigate interface. The Fortigate seems to be dropping all UDP 8888 traffic from the client to the FDP servers. I did a debug filter on one the FDP server ip' s and recieved a " Denied by forward policy check" I am sure my firewall policy allows these ports. Thanks
5 REPLIES 5
Carl_Wallmark
Valued Contributor

Hi, " Denied by forward policy check" means it cannot find the policy that would allow 8888 out on the internet. check to see if you can find a policy that would match, and also check policy order as your users are using Identity based policys, its a little bit tricky sometimes.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Not applicable

In the traffic log, the blocked traffic does not have usernames associated with it as opposed to the traffic that is allowed. I checked the policies and the associated policy that allows web traffic is at the top of rule base for that port. What UTM mechanism block 8888/UDP?
Not applicable

Could it be that the Forticlient services are try to contact the internet without using the domain user authentication and FSAE is blocking it?
Not applicable

Problem resolved. It did have to do with the policy base. I had to add a additional rule above the idenity rule that allowed the port
Carl_Wallmark
Valued Contributor

You cannot have ANY rules under the Identity Based Policys, they have to either be IN the policy or ABOVE the Identity Based Policy.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors