Skip to main content
SCSIraidGURU
New Member
December 11, 2016
Question

AT&T Arris NVG-589 to Fortinet 60E WAN 1 configuration

  • December 11, 2016
  • 4 replies
  • 8396 views

I set the NVG-589 into bridge mode following https://forums.att.com/t5/AT-T-Internet-Features/How-to-put-the-Motorola-NVG589-in-bridge-mode-or-as-close-as-you/td-p/3552057

WAN1 plugged into LAN port on NVG589. 

 

WAN 1 has the IP, gateway, etc.  I can get out to the internet.  I get DNS IP Connection errors.   My wife can't get Cisco Anyconnect to work.  I can use Forticlient to VPN into my data center.  Citrix works.   How did you connect your device to the cable modem? 

    4 replies

    SCSIraidGURU
    New Member
    December 12, 2016

    I opened a ticket with Fortinet. We tried Fortinet DNS, 8.8.8.8 and 8.8.4.4, and AT&T's DNS.  All give same errors.  We did a diag trace on DNS.  The outbound packets looked good.  It was the return packets from AT&T that were only UDP and not UDP 53.   DNS worked fine.  Sites resolved and opened.  I have a call with AT&T advanced network team for tonight.  589 bridge mode is working correctly to WAN 1.  Trace routes break after 224.2, the next hop from the 589. 

    SCSIraidGURU
    New Member
    December 13, 2016

    My wife's Cisco Anyconnect issue was on her work's end.  They gave her another site to use.  Still having DNS connection issues.  AT&T uses two copper pairs bonded together.  I wonder if it could be the issue with return packets. AT&T did not call tonight.

    MikePruett
    New Member
    December 13, 2016

    make sure fortiguard is set to run through 8888 instead of 53...I know on comcast it will reboot the modem and cause errors similar. Perhaps something of that nature is occurring here.

    SCSIraidGURU
    New Member
    December 13, 2016

    NVG-589 has everything disabled and is only in IP Passthrough mode.   The rules on the 60E are any traffic outbound for each port I am using.  WAN is anything inbound.   I think the issue is the two bound copper pairs are not working properly for the return packets.  

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.