This is an expected behavior on any FireWall when you do NMAP scan on TCP/2000 which is a SCCP port
TCP port 2000 as Skinny Client Call protocol (SCCP) traffic. SCCP is a Cisco proprietary protocol for VoIP.
So we do not recommend to do NMAP test on ports like(SCCP/SIP) TCP 2000, TCP 5060, 5061
Technical Note: FortiGate is not forwarding TCP ports 5060, 5061 and 2000
Technical Note: Disabling VoIP Inspection