Incoming ports
The following table identifies the incoming ports for FortiAnalyzer and how the ports interact with other products:
Product |
Purpose |
Protocol and Port |
---|---|---|
FortiAnalyzer
|
HA* |
TCP/5199 |
Log fetching on the log-fetch server side |
TCP/514 |
|
FortiAuthenticator |
Logging |
UDP/514 |
FortiAP-S |
Syslog, OFTP, registration, quarantine, Log & Report |
TCP/514 |
FortiClient
|
Logs from Windows/MacOS/Linux |
TCP/514 |
Logs from Chromebook |
TCP/8443 |
|
Fabric Member |
TLS/443 |
|
Syslog |
UDP/514 or TCP/514 |
|
FortiGate |
OFTP |
TCP/514 |
FortiMail |
Syslog |
UDP/514 |
FortiManager |
OFTP |
TCP/514 |
Syslog |
UDP/514 |
|
Management |
TCP/541 |
|
FortiNDR |
Logging |
UDP/514 |
FortiPortal |
API communications (JSON and XML) |
TCP/443, TCP/8080 |
Management
|
SSH |
TCP/22 |
HTTP |
TCP/80 |
|
HTTPS |
TCP/443 |
|
Web Service (SOAP/XML API) |
TCP/8080 |
|
JSON API (HTTPS/HTTP respectively) |
TCP/443, TCP/80 |
|
DC polling |
TCP/445 |
|
Log aggregation |
TCP/3000 |
*Only the acting Primary device will listen on this port.