Skip to main content
barisben
New Member
December 3, 2024
Question

Can't Access to the DR Site FW over VXLAN

  • December 3, 2024
  • 5 replies
  • 1145 views

Hey, we have VXLAN between DC and DR sites. We can access through the same subnet, so we can ping or access to the GUI. On the different subnets we can't access to the DR site FW with the HTTPs,PING or something but we can access to the DC site FW GUI or can ping it.

For example; We have 10.10.10.0/24 and 10.10.20.0/24 subnets. .1 is the VRIPs, .2 is the DC site FW, .3 is the DR site FW IPs. I can't access 10.10.20.3 from the 10.10.10.0/24 subnet but can access to the 10.10.20.2. When I try to ping and sniff from DR site FW it only gets icmp-requests but doesn't send reply packets. MTU sizes the same on both site. How could we solve that?

5 replies

sjoshi
Staff
Staff
December 3, 2024

Hi @barisben.

 

Can you please share the pcap on both nodes

diag sniff packet any 'host x.x.x.x and icmp' 4 0 l >> where x.x.x.x is the dst srv ip

Thanks, Salon
barisben
barisbenAuthor
New Member
December 4, 2024

On DC site FW;

2024-12-04 10:20:02.413843 NETWORK-MAN out 10.10.20.15 -> 10.10.10.3: icmp: echo request 2024-12-04 10:20:02.413848 NETWORK-MANvx out 10.10.20.15 -> 10.10.10.3: icmp: echo request 2024-12-04 10:20:03.413874 NETWORK-MAN out 10.10.20.15 -> 10.10.10.3: icmp: echo request 2024-12-04 10:20:03.413876 NETWORK-MANvx out 10.10.20.15 -> 10.10.10.3: icmp: echo request

 

On DR site FW;

2024-12-04 10:20:02.432951 NETWORK-MANvx in 10.10.20.15 -> 10.10.10.2: icmp: echo request 2024-12-04 10:20:02.432953 NETWORK-MAN in 10.10.20.15 -> 10.10.10.2: icmp: echo request 2024-12-04 10:20:03.433021 NETWORK-MANvx in 10.10.20.15 -> 10.10.10.2: icmp: echo request 2024-12-04 10:20:03.433023 NETWORK-MAN in 10.10.20.15 -> 10.10.10.2: icmp: echo request
sjoshi
Staff
Staff
December 4, 2024

I can see the traffic is reaching the DR site but not going out or not seeing the response back.

 

Run the debug flow

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/54688/debugging-the-packet-flow

Thanks, Salon
barisben
barisbenAuthor
New Member
December 4, 2024

DR site FW says "msg="reverse path check fail, drop"". So what can I do? Both sites have same subnets, what should I add to static route?

barisben
barisbenAuthor
New Member
December 4, 2024

On DC site FW;

2024-12-04 10:28:02.674223 NETWORK-MAN out 10.10.20.15 -> 10.10.10.3: icmp: echo request
2024-12-04 10:28:02.674225 NETWORK-MANvx out 10.10.20.15 -> 10.10.10.3: icmp: echo request

On DR site FW;

2024-12-04 10:28:02.696622 NETWORK-MANvx in 10.10.20.15 -> 10.10.10.3: icmp: echo request
2024-12-04 10:28:02.696623 NETWORK-MAN in 10.10.20.15 -> 10.10.10.3: icmp: echo request

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!