Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sushil
New Contributor

Custom service for non-standard port

Hi, I have a linux server behind FG110C.Linux server is published for public access on port 80.To access is for administration via SSH we customized the port on 1082. Added the custom service with source and destionation 1082 in all fields for low and high as well. Tried accessing it but it didn' t allowed access.We opened TCP and UDP port (under predefined services) and it allowed access for inbound policy.But I think that is a bad practice hence removed TCP and UDP as well. Finally we modified the source service 0-65535 and destionation as 1082-1082 for SSH allow and it worked.Is it safe to run it like this?What is the reason for this behaviour? In order to access this linux server from remote branch office lan behind FG80C we again have to specifiy 0-65535 under source and 1082-1082 under custom service. Is it possible if we can use some inspection technique (used in cisco ASA) to open just 1082 and inspecting the traffic? Reg, Sushil
1 REPLY 1
FortiRack_Eric
New Contributor III

It is save that it works like this, it' s by design. It' s basic networking principles. Otherwise only 1 connection would be possible. By rule of thumb all source ports are randomly chosen. Some protocols can be inspected, but SSH is not one of them Regards, Eric

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Labels
Top Kudoed Authors