Skip to main content
New Contributor III
December 3, 2009
Question

Cannot acces via web interface

  • December 3, 2009
  • 10 replies
  • 8388 views
Hello, I was connected via web interface to our Fortinet 60B firewall, checking configuration when, suddenly, the web borwser lost the connection and afterwards I cannot acces to the firewall via web anyway. The error that shows me is that the server is lasting too much and I cannot access. I' ve tried to connect via console and I can perfectly. I did a reboot via console but this doesn' t work. Would be possible any configuration that I' ve changed by mistake that cannot let me access via web???? Thanks

    10 replies

    rwpatterson
    New Member
    December 3, 2009
    Welcome to the forums. Anything is possible. Do you recall your last steps? Does it still seem to be passing traffic correctly? Is it in NAT/Route mode or transparent mode? Some good diagnostic commands from the CLI: To find the interface settings:
    #show system interface
    To find the admin source options:
    #show system admin
    To find the routing information:
    #show router static
    That should be enough to get you back on track. Good luck
    New Contributor III
    December 3, 2009
    Hello! thanks for your helping. I' ve typed the commands and here is what it says: # show system interface config system interface edit " wan1" set vdom " root" set ip 192.168.1.10 255.255.255.0 set allowaccess ping https ssh set type physical set alias " OUT" next edit " wan2" set vdom " root" set allowaccess ping set status down set type physical next edit " dmz" set vdom " root" set status down set type physical next edit " internal" set vdom " root" set ip 192.168.2.1 255.255.255.0 set allowaccess ping https ssh http set type physical next end # show system admin config system admin edit " admin" set accprofile " super_admin" set vdom " root" config dashboard edit " sysinfo" set column 1 next edit " licinfo" set column 1 next edit " jsconsole" set column 1 next edit " sysop" set column 2 next edit " alert" set column 2 next edit " sysres" set column 2 next edit " statistics" set column 2 next end set password ENC AK1E**** next edit " mperez" set trusthost1 192.168.2.0 255.255.255.0 set accprofile " admin_monitor" set vdom " root" config dashboard edit " sysinfo" set column 1 next edit " licinfo" set column 1 next edit " jsconsole" set column 1 next edit " sysres" set column 1 next edit " sysop" set column 2 next edit " alert" set column 2 next edit " statistics" set column 2 next end set password ENC AK1T*** next edit " rabad" set accprofile " super_admin" set vdom " root" config dashboard edit " sysinfo" set column 1 next edit " licinfo" set column 1 next edit " jsconsole" set column 1 next edit " sysres" set column 1 next edit " sysop" set column 2 next edit " alert" set column 2 next edit " statistics" set column 2 next end set password ENC AK**** next edit " arista" set accprofile " super_admin" set vdom " root" config dashboard edit " sysinfo" set column 1 next edit " licinfo" set column 1 next edit " jsconsole" set column 1 next edit " sysres" set column 1 next edit " sysop" set column 2 next edit " alert" set column 2 next edit " statistics" set column 2 next end set password EN***** next end # show router static config router static edit 1 set device " wan1" set gateway 192.168.1.1 next end
    rwpatterson
    New Member
    December 3, 2009
    From what it looks like, mperez can only get in from the internal interface, while the others can get in from WAN1 additionally. Access from internal should be http, https, ssh and ping. How are you trying to get into the device?
    New Contributor III
    December 3, 2009
    Hi rwpatterson!: I' m a JRuben mate and we are working together over same firewall. We use to login to firewall, user: " admin" , by http. But the problem is the graphical login interface is not shown in browser, the firewall is running and working perfectly. Is just we can' t access to graphical configuration interface . Thanx in advance! :D
    rwpatterson
    New Member
    December 3, 2009
    Are you trying from the inside interface (internal) or the outside interface (WAN1)?
    New Contributor III
    December 3, 2009
    Hi: We are trying it from ' internal' .
    rwpatterson
    New Member
    December 3, 2009
    Can you ping 192.168.2.1? If so, you should be able to browse in via HTTP or HTTPS. Are you on the interface subnet (192.168.2.0/24)?
    New Contributor III
    December 3, 2009
    Hi: I do ping 192.168.2.1 and it works I paste ipconfig from my lap: ==================================== C:\Documents and Settings\Vicente>ipconfig Configuración IP de Windows Adaptador Ethernet VMware Network Adapter VMnet8 : Sufijo de conexión específica DNS : Dirección IP. . . . . . . . . . . : 192.168.6.1 Máscara de subred . . . . . . . . : 255.255.255.0 Puerta de enlace predeterminada : Adaptador Ethernet VMware Network Adapter VMnet1 : Sufijo de conexión específica DNS : Dirección IP. . . . . . . . . . . : 192.168.44.1 Máscara de subred . . . . . . . . : 255.255.255.0 Puerta de enlace predeterminada : Adaptador Ethernet Conexiones de red inalámbricas : Estado de los medios. . . .: medios desconectados Adaptador Ethernet Conexión de área local : Sufijo de conexión específica DNS : CONTROLADOR Dirección IP. . . . . . . . . . . : 192.168.2.96 Máscara de subred . . . . . . . . : 255.255.255.0 Puerta de enlace predeterminada : 192.168.2.1 ======================================
    rwpatterson
    New Member
    December 3, 2009
    What happens when you try to get to: 1) http://192.168.2.1 or 2) https://192.168.2.1 They should work
    New Contributor III
    December 3, 2009
    nothing happens. error page appears like when page does not exists.
    rwpatterson
    New Member
    December 3, 2009
    What firmware version are you running? First line of
    #show full-configuration
    Also how long has this device been running (last reboot)?
    New Contributor III
    December 3, 2009
    What firmware version are you running? First line of #show full-configuration Also how long has this device been running (last reboot)?
    Hi!: I' m not in the office, in 13 hours I' ll come back and will answer your first question. about how long has been running. it has been running around 24 hours since las reboot(yesterday), by the way, it was rebooted as try to fix graphical login page. The really strange thing is I was connected to graphical interface when device " lost connection" . Thank you very much
    rwpatterson
    New Member
    December 3, 2009
    13 hours is 4 AM here. I' ll talk with you later tomorrow! LOL By any chance, did you create any virtual IPs?
    New Contributor III
    December 3, 2009
    By any chance, did you create any virtual IPs?
    Hi: Here it' s 22:50. I think I didn' t create any virtual IPs but now you tell about it... I have some doubt now. How can I check it and if so how can I fix that by CLI. Maybe it could be created by accident.You think this may be one reason so it does not work login interface? I really think so. Regards!
    rwpatterson
    New Member
    December 3, 2009
    # show firewall vip
    New Contributor III
    December 3, 2009
    Hi!: that is vIPs show firewall vip config firewall vip edit " RDP celinasp03.interligare.com" set extintf " wan1" set portforward enable set mappedip 192.168.2.212 set extport 3389 set mappedport 3389 next edit " VPN CeCubo" set extintf " wan1" set portforward enable set protocol udp set mappedip 192.168.2.250 set extport 24005 set mappedport 24005 next edit " OpenKM wilco.interligare.com" set extintf " wan1" set portforward enable set mappedip 192.168.2.42 set extport 8080 set mappedport 8080 next edit " SVN wilco.interligare.com" set extintf " wan1" set portforward enable set mappedip 192.168.2.42 set extport 443 set mappedport 443 next edit " MemexRadiohead" set extintf " wan1" set portforward enable set mappedip 192.168.2.41 set extport 9001 set mappedport 9001 next edit " Xplanner Artemisa" set extintf " wan1" set portforward enable set mappedip 192.168.2.45 set extport 70 set mappedport 80 next edit " FTP caliope.interligare.com" set extintf " wan1" set portforward enable set mappedip 192.168.2.46 set extport 21 set mappedport 21 next edit " pop test" set extintf " wan1" set portforward enable set mappedip 192.168.2.58 set extport 110 set mappedport 110 next edit " Tomcat la Caixa - artemisa" set extintf " wan1" set portforward enable set mappedip 192.168.2.189 set extport 90 set mappedport 8080 next edit " Wilco SSH" set extintf " wan1" set portforward enable set mappedip 192.168.2.42 set extport 22 set mappedport 22 next edit " Servidor Log Reddoor" set extintf " wan1" set portforward enable set mappedip 192.168.2.97 set extport 8081 set mappedport 8081 next edit " Servidor SVN" set extintf " wan1" set portforward enable set mappedip 192.168.2.97 set extport 3690 set mappedport 3690 next edit " caliope" set extip 192.168.2.1 set extintf " wan1" set portforward enable set mappedip 192.168.2.46 set extport 80 set mappedport 80 next edit " Patriarch Artemisa" set extintf " wan1" set portforward enable set mappedip 192.168.2.45 set extport 9002 set mappedport 9001 next edit " MMOLINAV1" set extintf " wan1" set portforward enable set mappedip 192.168.2.189 set extport 1723 set mappedport 1723 next edit " MMOLINAV2" set extintf " wan1" set portforward enable set protocol udp set mappedip 192.168.2.189 set extport 47 set mappedport 47 next edit " Servidor SVN - SSH" set extintf " wan1" set portforward enable set mappedip 192.168.2.97 set extport 28690 set mappedport 22 next end I only change some configuration in ' caliope' edit " caliope" set extip 192.168.2.1 set extintf " wan1" set portforward enable set mappedip 192.168.2.46 set extport 80 set mappedport 80 Thank you!
    New Contributor III
    December 4, 2009
    Hi!: I fixed the problem. It was the field ' set extip 192.168.2.1' . I unset it and login works! Thank you for help and for your time. It was really usefull cya soon!
    rwpatterson
    New Member
    December 4, 2009
    A little sleep helps! Glad you figured it out.