Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ncfom
New Contributor

Block port 22 SSH

Hy Everbody !

 

I want to disable in my fortigate 90 the SSH port 22.

It is necessary to create a policy or I need to disable an option ?

 

Thank you !

 

2 Solutions
Nishad
New Contributor III

Do you enable ssh to form a WAN interface? if possible please share the screenshot.

 

Regards,

Nishad

View solution in original post

Regards, Nishad
Dave_Hall
Honored Contributor

Hi Cosmin.

 

What exactly are you trying to do?  The info provided by Nishad is for blocking port 22 access to the fgt from the interface (usually a WAN port).  If you are trying to block people (devices) from accessing port 22 at any addresses on the Internet (e.g. outside your fgt) you need to craft a firewall policy that blocks that port from Internal->WAN1 (e.g. connections going out the WAN port).

 

BTW I suggest leaving the ssh port value setting at 22 but uncheck SSH on the interface (e.g. WAN1) if you do not want people/devices attempting to access your fgt from outside. 

 

Haven't tested this myself, but I assume the fgt will assume the default value for the SSH port will always be what is defined under system global.

 

system global set admin-ssh-port <value> end

(edited)

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

View solution in original post

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
8 REPLIES 8
Nishad
New Contributor III

You just need to untick the ssh from the interface. Or else from system setting, you can change the ssh port from 22 to custom port.

Regards,

Nishad

Regards, Nishad
ncfom
New Contributor

Thank you for you answer.

I untick the ssh from the interface (network - interface) and I modify the ssh port (system-settings) from 22 to a custom port but is still open when I check on the internet

Other sugestions ?

Nishad
New Contributor III

Do you enable ssh to form a WAN interface? if possible please share the screenshot.

 

Regards,

Nishad

Regards, Nishad
Dave_Hall
Honored Contributor

Hi Cosmin.

 

What exactly are you trying to do?  The info provided by Nishad is for blocking port 22 access to the fgt from the interface (usually a WAN port).  If you are trying to block people (devices) from accessing port 22 at any addresses on the Internet (e.g. outside your fgt) you need to craft a firewall policy that blocks that port from Internal->WAN1 (e.g. connections going out the WAN port).

 

BTW I suggest leaving the ssh port value setting at 22 but uncheck SSH on the interface (e.g. WAN1) if you do not want people/devices attempting to access your fgt from outside. 

 

Haven't tested this myself, but I assume the fgt will assume the default value for the SSH port will always be what is defined under system global.

 

system global set admin-ssh-port <value> end

(edited)

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
ncfom

Thank you for your answers.

 

I want to block SSH port 22 from the internet to my Fortigate

Bellow I have made some printscreens from my device with some settings that I have made regarding this port 22

As you all see I changed the port from 22 to 2222, I uncheck the box SSH

 

ncfom
New Contributor

And the other printscreen

 

 

ede_pfau

You've allowed access from FortiCloud - this might well use port 22. Check with FTNT docs and the KB.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
rwpatterson
Valued Contributor III

ncfom wrote:

Thank you for you answer.

I untick the ssh from the interface (network - interface) and I modify the ssh port (system-settings) from 22 to a custom port but is still open when I check on the internet

Other sugestions ?

What are you checking, port 22 or your custom port? Also what are you trying to block access to? The Fortigate or a device behind it?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Labels
Top Kudoed Authors