Incoming ports
The following table identifies the incoming ports for FortiAnalyzer and how the ports interact with other products:
Product |
Purpose |
Protocol and Port |
---|---|---|
FortiAnalyzer
|
HA* |
TCP/5199 |
Log fetching on the log-fetch server side |
TCP/514 |
|
FortiAI |
Logging |
UDP/514 |
FortiAuthenticator |
Logging |
UDP/514 |
FortiAP-S |
Syslog, OFTP, registration, quarantine, Log & Report |
TCP/514 |
FortiMail |
Syslog |
UDP/514 |
FortiClient
|
Logs from Windows/MacOS/Linux |
TCP/514 |
Logs from Chromebook |
TCP/8443 |
|
Fabric Member |
TLS/443 |
|
Syslog |
UDP/514 or TCP/514 |
|
FortiPortal |
API communications (JSON and XML) |
TCP/443, TCP/8080 |
FortiGate |
OFTP |
TCP/514 |
FortiManager |
OFTP |
TCP/514 |
Syslog |
UDP/514 |
|
Management |
TCP/541 |
|
FortiRecorder |
Logging, management |
TCP/21, TCP/80, TCP/443, TCP/3011, TCP/3010 UDP/554 by default, but can change to TCP/554 |
Management |
SSH |
TCP/22 |
Web Admin |
TCP/80, TCP/443 |
|
REST API, XML API |
TCP/443 |
|
DC polling |
TCP/445 |
|
Log aggregation |
TCP/3000 |
*Only the acting Primary device will listen on this port.