Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

port opening

i need a little help here i want to open port 22 in the firewall to be use for SFTP and i dont know how since is my first time working with fortinet product any help will be welcome with open arms
7 REPLIES 7
Not applicable

Firewall -->Virtual IP --> Create New Give it a name SFTP -->External IP --> Internal IP Check Port Forwarding External port 22 Mapped to 22 click OK Create a policy Firewall --> Policy --> Create New Source WAN1 Source Address All (unless you want to restrict to a single address or group of addresses) Destination Internal Destination Address SFTP (or whatever you named the VIP) Service FTP Action Accept NAT (Checked) OK
abelio

Create a policy Firewall --> Policy --> Create New Source WAN1 Source Address All (unless you want to restrict to a single address or group of addresses) Destination Internal Destination Address SFTP (or whatever you named the VIP) Service FTP Action Accept NAT (Checked) OK
you won´t NAT that policy unless your sftp server requires receive queries only from internal ips. If you´ve defined VIP as port-forwarding to port 22, you will not define FTP service in the firewall policy, use custom one for SFTP or any regards

regards




/ Abel

regards / Abel
Not applicable

thanks for the help after i do the changes i have to restart the unit?
doshbass
New Contributor III

Nope, you should nevcer have to restart a Fortigate unless something goes very wrong
Still learning to type " the"
Still learning to type " the"
Not applicable

thanks for the correction it was late wasnt tinking straight!
Not applicable

i dp the chages but the port still closed, i verify it when try to uplod a file to the client sftp
red_adair
New Contributor III

can you post your config snippet from the VIP and the respective FW policy #sh fire vip #sh fire pol you also may try to watch packets using #diag sniff pack any ' tcp and port 22' 4 to see if packets are going forth/back. -R.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors