I have a forefront TMG 2010 server setup as my firewall. I have a new vault to cloud system setup for my backups. The traffic leaves on UDP 1197 but comes back on a variable port from 10,000 to 65,000. The vault people claim the issue is with my firewall but I have never once seen traffic come back in the firewall on 1197. I can see that the source port is 1197 but the destination port is 10,000 to 65,000. If the traffic came back in on destination port 1197 then I can forward that with no problem.
Can I forward based on source port and not destination port? Is the issue on the vault side?
Here is what they sent me to show the traffic is leaving their firewall no problem but it looks to me like it is trying to access port 62221 on my firewall and not 1197.
16:25:45.145024 IP 10.200.1.41.1197 > 209.242.XXX.XXX.62221: UDP, length 22