Hi all,
I have a RRAS server(Windws Server 2008) act like VPN ACCESS (I use protocol L2TP)
what is ports need to open in Fortigate 311B(firmware 5.2.1,build618) firewall to enable VPN I search in net and i found many port such as ESP, GRE, ISAKMP, L2tp, PPTP.......
I wan to use L2TP(IPsec) which exact port and protocols must be opened on Fortigate 311B?
Note: I am using Virtual-IP and port forwarding feature on Firewall 311B.
Thanks
Erdal
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
hi,
according to this page
you need the standard VPN ports udp/500 and udp/4500, but in addition the (port-less) ESP protocol. A VIP will only pass traffic which is not UDP or TCP if it is not port-forwarding (*). So you will need to make the VIP 1:1 which means this will consume one public IP address.
(*) for those who read carefully: port-forwarding VIPs will forward ICMP as well in FortiOS 5.2, even though it's portless as well. This had been a constant source of confusion over the past years so Fortinet finally agreed to give in and 'enlarge' the concept of a port-forwarding VIP.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.