Skip to main content
Contributor
January 21, 2010
Question

Can' t ping firewall

  • January 21, 2010
  • 5 replies
  • 3436 views
I' m trying to test a new firewall (we are soon to be replacing our current forinet firewall with a new one). What I' ve done is set my new FW up on a test network but on this test network I cant' ping the FW. I' ve checked the box for " ping" under System \ Network \ Port5 (this is the port i' m using to test). However it will not ping. On the LAN side I have a laptop plugged into a dumb switch with a static IP. It really doesn' t get any easier than my setup, it' s pretty much idential to a home setup. The FW is not on the Internet, I' m just trying to get laptop to ping the firewall, the FW DOES ping the laptop, but not the other way around, and I' ve checked and rechecked settings on the laptop. Any help would be greatly appreciated, Fortinet Support has not been responsive. I am using a FortiGate 110C v4.0,build0192,091222 (MR1 Patch 2)

    5 replies

    g3rman
    New Member
    January 21, 2010
    Hi Gunnar, welcome to the forums. Make sure your firewall admin accounts permit the IP address of your laptop to connect to the firewall.
    Contributor
    January 21, 2010
    I' m unsure what admin accounts have to do with anything. This is a routing issue. When the laptop sitting on the test network attempts to ping the firewall it fails. I can access the firewall just fine via a separate port. From the firewall I can even ping the laptop sitting on the test network, but the laptop cannot ping it' s gateway (the firewall). If any device can' t see or talk to it' s gateway anything beyond it' s network will be unavailable to it, which is exactly my issue. I' m trying to get my laptop to talk to it' s gateway and it' s not able to.
    Contributor
    January 21, 2010
    I drew up a diagram of what I' m trying to explain. I' m managing this network through a different port. The laptops can ping each other and the firewall can ping the laptops but the laptops can' t ping their gateway (the firewall).
    g3rman
    New Member
    January 21, 2010
    Check out this blog post: http://firewallguru.blogspot.com/2009/02/securing-firewall-administrator-access.html If you set your admin accounts for trusted hosts that don' t include the 192.168.1 network you will not even be able to ping the firewall, regardless of routing.
    Contributor
    January 21, 2010
    I am too embarrased to talk, I honesty thought you were crazy, yet you fixed my issue, thank you so much.