Traffic Types and TCP/UDP Ports used by Fortinet

Network traffic originating from FortiGate units (not passing through FortiGate units) is used for sending log messages to remote log servers, sending SNMP traps, resolving network names using DNS, and so on.

Service Ports
Syslog. All FortiOS versions use syslog to send log messages to remote syslog servers. FortiOS v2.80 and v3.0 also use syslog to send log messages to FortiAnalyzer.UDP 514
Alert email and quarantine auto submit (using encrypted SMTP email)TCP 25
SNMP trapsUDP 162
DNS lookupUDP 53
NTP synchronizationUDP 123

FortiGate units communicate with the FortiGuard Distribution Network (FDN) using the following ports. The ports that FortiClient and FortiManager use to communicate with the FDN are also listed below.

Service Ports
FortiOS v3.0 FortiGuard Antivirus updatesTCP 443
FortiOS v2.80 FortiGuard Antivirus updatesTCP 443 TCP 8443
FortiOS v2.50 FortiGuard Antivirus updatesTCP 8890
FortiClient FortiGuard Antivirus updatesTCP 80
FortiOS v3.0 FortiGuard Web Filtering and AntispamUDP 53 (default) or UDP 8888
FortiOS v2.80 FortiGuard Web FilteringUDP 8888
FortiOS v2.80 FortiGuard Antispam (FortiShield)UDP 8889
FortiManager v3.0 FortiGuard Web Filtering and AntispamTCP 443 and TCP 8890

When operating with the Factory default configuration, FortiGate units do not accept TCP or UDP connections on any port. The one exception is the default internal interface, which accepts HTTPS connections on TCP port 443.

The following table lists the TCP and UDP ports that FortiGate units listen on when you enable various configuration options.

Service Ports
Telnet Administrative Access to the CLITCP 21
SSH Administrative Access to the CLITCP 22
HTTP Administrative Access to the Web-based managerTCP 80
HTTPS Administrative Access to the Web-based managerTCP 443
Default port to use for override authenticationTCP 8008
FortiGuard Distribution Network (FDN) Antivirus and IPS push updatesTCP 9443
SSL VPN connections (SSL VPN enabled)TCP 10443
FortiOS v3.0 VPN Policy Distribution to FortiClient (enabled from CLI using config vpn ipsec forticlient).TCP 8900
 
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值