Skip to main content
kingtech
Visitor III
April 13, 2022
Question

Cannot ping public ip internally but can from outside

  • April 13, 2022
  • 18 replies
  • 19584 views

Hello, i am facing this problem for the first time and i don't know where im doing it wrong. I have to access my own ip address both from inside and outside the network . The problem is that from outside i am able to connect to the ip and do my stuff, but when i am connected locally i can't.. 

I tried pinging the address from the fortigate CLI and i get no response. If i ping it from outside (another public ip, or by using a smartphone 4g) it works like a charm. Can someone explain me why please?

 

I have a fortigate 60E with 7.2.0 Build 1157

18 replies

tio3udes
Explorer III
April 13, 2022

The public IP address ou trying to ping, is configured in one of the fortigate's interfaces?

kingtech
kingtechAuthor
Visitor III
April 14, 2022

The WAN1 of the fortigate is connected to the router like i always do on fortigates. The problem is that from the fortigate i can't ping my OWN ipaddress, the one i am connected to. The same ip has no problem from outside the network

tio3udes
Explorer III
April 14, 2022

So the firewall does not have an public ip of it's own? What do you mean as your own IP address? The router IP, the Fortigate IP?

 

If it's a fortigate IP, the ping is enabled on the interface?

pminarik
Staff
Staff
April 14, 2022

If the public IP is directly configured, or owned by, the FortiGate, then for the LAN->WAN direction to reach the public IP, you will need a firewall policy for exactly this direction.

This may be a bit more complicated if you're trying to reach a service through a VIP. (let us know if this is the case)

 

If the public IP is actually located on the router upstream of the FortiGate (the idea being that the router might be doing some DNAT/port-forwarding, or filtering traffic in the direction inbound to your FortiGate), then you will need to check with someone managing that router. Maybe it just doesn't allow the traffic to flow in such direction?

 

kingtech
kingtechAuthor
Visitor III
April 19, 2022

Sorry for the easter delay .

The public ip is on the router, where i have a NAT 1:1 on the local ip 192.168.1.15 where i connected the FortiGate with the WAN port.

as i replied to tio3udes: ping is enabled and everything is working from outside the network (smartphone 4g, another connection etc). When im connected to the switch or directly to the Forti, or on the FortiCLI itself, i can't ping or interact with anything on my Public IP

pminarik
Staff
Staff
April 19, 2022

In that case I would suggest running a sniffer on the FortiGate to find out whether you are receiving the ping packet, when it goes from the WAN direction, at all.

 

diag sniffer packet <wan> "host <source-ip> and icmp" 4 0 a # test now CTRL+C to stop the capture

 

replace <wan> with the actual name of your "WAN" interface (the one pointing to the router upstream), and <source-ip> with the public IP of your client-device sending the test-pings.

If you see the packet arrive, some further investigation on the FortiGate will be needed. But if you don't see it arriving at all, you'll need to check futher upstream (router or ISP), because there's nothing we can do on the FortiGate if the packet does not reach it at all.

seshuganesh
Staff
Staff
April 21, 2022

Hi Team,

 

From the previous sniffer, we could not able to observe any output. I will request you to run the sniffer in this way:

diag sniffer packet any 'host 8.8.4.4 and icmp' 4 0 a

 

Once you enter this sniffer, ping to 8.8.4.4 from the firewall other console and share the result with us.

 

kingtech
kingtechAuthor
Visitor III
April 21, 2022

Here are the results:

 

FortiGate # diag sniffer packet any 'host 8.8.4.4 and icmp' 4 0 a
interfaces=[any]
filters=[host 8.8.4.4 and icmp]
2022-04-21 09:27:04.258525 wan1 out 192.168.1.15 -> 8.8.4.4: icmp: echo request
2022-04-21 09:27:04.288113 wan1 in 8.8.4.4 -> 192.168.1.15: icmp: echo reply
2022-04-21 09:27:05.269305 wan1 out 192.168.1.15 -> 8.8.4.4: icmp: echo request
2022-04-21 09:27:05.298873 wan1 in 8.8.4.4 -> 192.168.1.15: icmp: echo reply
2022-04-21 09:27:06.279273 wan1 out 192.168.1.15 -> 8.8.4.4: icmp: echo request
2022-04-21 09:27:06.309581 wan1 in 8.8.4.4 -> 192.168.1.15: icmp: echo reply
2022-04-21 09:27:07.289303 wan1 out 192.168.1.15 -> 8.8.4.4: icmp: echo request
2022-04-21 09:27:07.318825 wan1 in 8.8.4.4 -> 192.168.1.15: icmp: echo reply
2022-04-21 09:27:08.299284 wan1 out 192.168.1.15 -> 8.8.4.4: icmp: echo request
2022-04-21 09:27:08.329063 wan1 in 8.8.4.4 -> 192.168.1.15: icmp: echo reply
^C
10 packets received by filter
0 packets dropped by kernel

seshuganesh
Staff
Staff
April 21, 2022

 

We could see the reply is request and reply is happening. But ealier you mentioned, you are not able to access any thing in the internet from the firewall.

Could you please reclarify?

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!