Skip to main content
blackcell94
New Member
May 4, 2021
Question

Cannot Ping Computer from other Vlan

  • May 4, 2021
  • 1 reply
  • 2966 views

I would like to seek your help guys , I was little bit confuse about this FortiGate configuration , I already setup the Vlan20 IP address range of 20.20.20.0/24 and Vlan30  30.30.30.0/24 for testing purposes and it looks fine from the start and I try to ping the 20.20.20.1 VLAN20  inside the Vlan 30 and it reply no problem I also ping the 30.30.30.1 VLAN30 inside the Vlan 20 and its the same without problem and both VLAN’s have a internet and have DHCP Server . but when I try to add client computers inside the Vlan20 and Vlan30 the problem arise and I try to ping the other client inside the VLan20 like 20.20.20.2 to 20.4 inside VLan30  no reply RTO. any advice much appreciated . I'm just new in Fortinet I only learn it few days ago it seems for me a rules or policy issue. thank you in advance

    1 reply

    sw2090
    SuperUser
    SuperUser
    May 4, 2021

    do your clients have the FGT as Gateway?

    does the FGT have the correct polices to allow trafic i both directions?

     

    blackcell94
    New Member
    May 4, 2021

    The client gateway is the gateway of the VLAN

    here are ip

     

    VLAN 20 - 20.20.20.0/24 IP ADDRESS AND SUBNET

                    20.20.20.1 -GATEWAY OF VLAN 20

     

    VLAN 30 - 30.30.30.0/24 IP ADDRESS AND SUBNET

                    30.30.30.1 -GATEWAY OF VLAN 30

     

    Can you give me a sample policy that is working so that i can check on my side