Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aagrafi
Contributor II

Is something special with TCP port 5858?

Hello,

The issue I describe below happened in a FAD actually, but I'm using this forum since I don't see any activity in the FAD forum.

 

I received a vulnerability report saying that TCP port 5858 in our FAD (VM, version 4.6) is open to administrative access. I verified with Wireshark that when I telnet the FAD at port 5858, the FAD responds with a SYN, ACK. Next, I set telnet to be at port 5858 and then removed telnet from allow access, and still the FAD responds with SYN, ACK when I telnet at 5858.

 

This behavior look very strange to me and I would like to know if there is something special for TCP port 5858. For example, when I set telnet at port 5860, the FAD immediately sends an RST. Do you know why it ACKs when the session opens at 5858?

 

Thanks

0 REPLIES 0
Labels
Top Kudoed Authors