Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
trubendall
New Contributor

PCI and port 1000 & 1003

We are failing an external PCI scan because port 1000 and 1003 are open and listening on old security protocals.  How can I disable these ports?  I read that they are disabled by default, but they seem to be open.  It looks like they are for Authentication.  Thanks in advance.

4 REPLIES 4
NeilG
Contributor

You say 1000/1003 are listening on old-security protocols. Whose old protocols? built-in fortigate or your own?

What is the Fortigate model and firmware?

 

Have you looked at your local-in policies? 

 

Have you opened a support ticket?

dmcquade
New Contributor III

These are related to the keepalive for user authentication and not necessarily traffic trying to communicate outbound. You will see these messages when you have the logging set to log all traffic.

 

HTH

d

emnoc
Esteemed Contributor III

The ports are controlled via sys global

 

e.g

 

 set auth-http-pot

 set auth-https-port

 

If you have  fwpolicy enable with user auth , then these are open.

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
darwin_FTNT

I filed a bug report for this 0488051.  Hopefully it would be fixed if needed.  So far it seems fine if open... ???

Labels
Top Kudoed Authors