Skip to main content
Mx7733
New Member
November 14, 2019
Solved

Browser cant reach destination, telnet can

  • November 14, 2019
  • 6 replies
  • 7467 views

Hi there,

 

Let me start off by saying I'm new to Fortigate. I just passe NSE-2 and are currently 'studying' NSE-3 and afterwards NSE-4. I work for a small service provider and kind of got the firewall thrown in my lap. Not that i mind, I like the challenge, but still there is a lot to learn...

 

With that in mind, I ran in to a conundrum. One of our clients has 9 stores with customer counters. One of these stores cannot connect with the server for updates. They all go though the same FW...

 

So i made a new policy for this location and get client-RST or Accept: IP connection error when using a laptop to go to the portal the counter should go. When I Telnet to the location I can reach it without problems or errors on the FW.

 

Can anyone tell me what I can troubleshoot next?

 

If anymore info is needed please tell me what you need. Thanks in advance

    Best answer by Toshi_Esumi

    Since you're a service provider, I assume those FGTs (or just one?) are brand-new. Then my best advise would be to use TAC support wisely as needed.

    Anyway, you mentioned "all go through the same FW". Is it at their HQ location? How those stores can get to the "FW"? Over VPNs? Give us a little more info about the topology. 

    6 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    November 14, 2019

    Since you're a service provider, I assume those FGTs (or just one?) are brand-new. Then my best advise would be to use TAC support wisely as needed.

    Anyway, you mentioned "all go through the same FW". Is it at their HQ location? How those stores can get to the "FW"? Over VPNs? Give us a little more info about the topology. 

    Mx7733
    Mx7733Author
    New Member
    November 27, 2019

    I don't understand what a FGT is..

    But we host their VPN and their breakout to the internet is through the firewall. Which I try to manage, poorly it seems. 

     

    I've been googling the error messages, but come up short. How do I see what this means:

    ActionAccept: IP connection errorThreat262144Policy37Policy UUIDbe146836-0133-51ea-36c1-0b2da7f5b7a8Policy Typepolicy

     

    Does this mean an NAT error because op the IP? Shouldn't this be an port error then? And why does thsi have a green 'check' under result, even thou it doesn't work. 

    And at the same time i have an unchecked result for;

    Actionclient-rstPolicy37Policy UUIDbe146836-0133-51ea-36c1-0b2da7f5b7a8Policy Typepolicy

     

    I do not understand what i should do with this error.

     

    Regards,

     

    Marnix

     

    ede_pfau
    SuperUser
    SuperUser
    November 27, 2019

    FGT = Fortigate

     

    from the serial numbers "FGT-xxx" :)

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.