Skip to main content
gashjaei
Explorer II
December 23, 2021
Solved

Access Private Portal

  • December 23, 2021
  • 12 replies
  • 9198 views

Hello Experts, 

 

I would like to access one of local address in another local network but still no news. 

On Fortigate 80F(FortiOS v7.0.2)  I set something that  you can see below:

 

Firewall address:

edit "LAN-CUP-10.2.x.x/24"
set uuid e1e4a43a-4234-51ec-1d33-78ef82b1ea54
set subnet 10.2.x.x 255.255.255.0

 

config firewall policy

edit 17
set name "Any to CUP"
set uuid cc69133e-6340-51ec-a051-06a9cb3d812b
set srcintf "any"
set dstintf "any"
set action accept
set srcaddr "all"
set dstaddr "CUP-Portal" "LAN-CUP-10.2.x.x/24" "Portal"
set schedule "always"
set service "ALL"
set ssl-ssh-profile "Test for Portal CUP"
set logtraffic all

There is also static route for destination network. 

 

Inside the Firewall  I can ping 10.2.x.x/24 but from source network (192.168.10.x ) can not ping 10.2.x.x/24.

 

Do you have any ideas?

 

Thank you so much 

 

Best,

Ghasem

 

 

Best answer by gashjaei

Hello 

Finlay got the answer, 

 

remove the policy and enable NAT. 

tnx 

Ghasem

12 replies

Julien87
Contributor II
December 23, 2021

Hi Ghasem,

 

Have you check if you see the packet icmp in firewall ?   you can check this one with diagnose sniffer packet any 'icmp and host 10.2.x.x' 4      

 

If you look the icmp packet, you can check flow diagnostic. To check why the packet is blocked.

https://docs.fortinet.com/document/fortigate/6.2.3/cookbook/54688/debugging-the-packet-flow

 

Best regards, 

 

 

gashjaei
gashjaeiAuthor
Explorer II
December 23, 2021

Hello Julien,

 

Yes, I have also tried this and when I ping the destination everything goes well. but can not open the page in local machine . 

 

Tnx

Julien87
Contributor II
December 23, 2021

Hi, 

 

can you post the return diag sniffer ?  because in your post i see source network (192.168.10.x ) can not ping 10.2.x.x/24...  you do have change configuration for that?    

You can send the result for diag sniffer packet any 'host x.x.x.x and port 443' 4   if your portal is in HTTPS with standard port.

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!