Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Erdal
New Contributor

VPN protocols and ports trought Fortigate311B

Hi all,

I have a RRAS server(Windws Server 2008) act like VPN ACCESS (I use protocol L2TP) 

what is ports need to open in Fortigate 311B(firmware 5.2.1,build618) firewall to enable VPN I search in net and i found many port such as ESP, GRE, ISAKMP, L2tp, PPTP.......

I wan to use L2TP(IPsec) which exact port and protocols must be opened on Fortigate 311B?

Note: I am using Virtual-IP and port forwarding feature on Firewall 311B.

Thanks

Erdal

1 REPLY 1
ede_pfau
SuperUser
SuperUser

hi,

 

according to this page

http://blogs.technet.com/b/rrasblog/archive/2006/06/14/which-ports-to-unblock-for-vpn-traffic-to-pas...

 

you need the standard VPN ports udp/500 and udp/4500, but in addition the (port-less) ESP protocol. A VIP will only pass traffic which is not UDP or TCP if it is not port-forwarding (*). So you will need to make the VIP 1:1 which means this will consume one public IP address.

 

 

(*) for those who read carefully: port-forwarding VIPs will forward ICMP as well in FortiOS 5.2, even though it's portless as well. This had been a constant source of confusion over the past years so Fortinet finally agreed to give in and 'enlarge' the concept of a port-forwarding VIP.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors