Skip to main content
player
New Member
August 16, 2015
Question

5.2.4

  • August 16, 2015
  • 5 replies
  • 8386 views

Hi all,

 

After upgrading to 5.2.4 , all some SSL traffic is not passing through and management traffic using SSH/HTTPS to the firewall is not working, there are no proxy configuration nor SSL inspections or any mgmt hardening.

 

Has anyone seen this kind of behavior?

 

    5 replies

    emnoc
    New Member
    August 16, 2015

    I'm assuming it was working b4  5.2.4 upgrade? If yes than diag debug flow the traffic and see what shows up;

     

    e.g

     

    diag debug reset

    diag debug en

    diag debug flow filter port 443

    diag debug flow show console enable

    diag debug flow trace start 100

     

     

    Post the output here and ensure allow access https is still enabled on the interface(s) that your expecting management.

     

    When your done,

     

    diag debug reset 

    diag debug disable

     

     

    You might have to open a ticket or revert back to 5.2.3

    vjoshi_FTNT
    Staff
    Staff
    August 17, 2015

    Hello,

     

    There is a known issue recently reported on V5.2.4 where only the ssl traffic is effected.

     

    Ping works fine.

    This is normally seen in a dual wan scenario where https request is received on one interface and response is sent out on another.

     

     As suggested by earlier post, run the debug flow and see if the above said symptoms are seen your case.

    player
    playerAuthor
    New Member
    August 17, 2015

    well, it seems like the firewall is blocking traffic to itself for some reason : (no trusted hosts and ssh is allowed on the interface)

     

    id=20085 trace_id=2 func=init_ip_session_common line=4527 msg="allocate a new session-0000038f" id=20085 trace_id=2 func=fw_local_in_handler line=382 msg="iprope_in_check() check failed on policy 0, drop" id=20085 trace_id=3 func=print_pkt_detail line=4378 msg="vd-in received a packet(proto=6, 1.1.1.1:3555->1.1.1.9:22) from wan2.

     

    also tried to ssh the firewall to itself :

     

    ssh: connect to host 1.1.1.9 port 22: Connection refused

    emnoc
    New Member
    August 17, 2015

    On the wan interface what does your set allow access show  ( ssh ? )?

     

    Ken

     

     

    vjoshi_FTNT
    Staff
    Staff
    August 18, 2015

    Hello,

     

    I think, the port on which the Fortigate is listening for SSH must be changed. It is worth to check and confirm under System > Admin > Settings.

     

     

     

     

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!