关于Fortigate 100E路由器发送携带TCP端口的ICMP数据包的技术疑问
Hey there, let's unpack what you're observing—it's definitely a quirky ICMP pattern, but there's a solid explanation tied to how Fortigate devices work.
First off, you're right that ICMP is a layer 3 control protocol, but it's important to remember that ICMP packets can carry upper-layer protocol headers (like TCP) as part of their payload. This is actually standard behavior defined in relevant RFCs, and Fortigate leverages this for specific monitoring or security-related tasks.
Now, onto the one-way traffic with fixed source port 443 and varying destination ports: this looks exactly like a port-focused health check or availability probe that the Fortigate is running against your application server. Here's why this makes sense:
- Fortigate often uses dedicated internal ports (or well-known ports like 443, which is its default HTTPS management port) as the source for these probes to make the traffic easily identifiable.
- Instead of sending raw TCP SYN packets (which might be blocked by other network rules or server firewalls), the device wraps the TCP port information inside an ICMP packet. This is a common workaround to ensure the probe can reach the server even if direct TCP traffic is restricted.
- This could be tied to a custom health check rule an admin configured, or it might be part of Fortigate's built-in features like load balancing (if the server is part of a backend pool) or application availability monitoring. The varying destination ports suggest it's checking multiple services on the server to confirm they're reachable.
Since you don't have access to the router's config, you can't confirm this directly, but based on the traffic signature, this is almost certainly intentional behavior from the Fortigate, not malicious activity. It's just the device doing its job to monitor the health of your application server.
备注:内容来源于stack exchange,提问作者Deluccio

