Skip to main content
Dom5
New Member
March 4, 2020
Question

Cannot ping the internal interface of the Fortigate 100D

  • March 4, 2020
  • 10 replies
  • 14741 views

Good evening all,

 

I have a configuration that I am not sure why it does not work. 

 

This is Fortios 6.2.2

 

I attached the topology.

Static route on FTG is 

10.10.1.0/24 to 10.10.1.254

10.10.101.0/24 to 10.10.1.254

10.10.102.0/24 to 10.10.1.254

 

VLAN90 - 10.10.1.1/24 with default gateway 10.10.1.254

 

 

ping from Cisco 3750 switch to SVI interface of VLAN 101, has ping reply

ping from Cisco 3750 switch to FTG - 10.10.1.1, has ping reply

ping from PC1 to PC2, has ping reply

ping from PC2 to PC1, has ping reply

ping to 10.10.1.254 has ping reply

ping from PC2 to 10.10.1.1(FTG internal interface), has no reply

Ping from PC2 to WAN1 also has no reply

 

It seems the out going routing from different VLAN from VLAN90 will not be able to reach the internal FTG or external FTG WAN interface. 

 

Do you know why it does not be able to ping? I cannot ping 8.8.8.8 as well. 

 

PS: the ping has enabled on the interface. 

    10 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    March 4, 2020

    Why is the default GW at the FGT toward Cisco while the internet circuit is terminated at the FGT?

    Dave_Hall
    New Member
    March 4, 2020

    Also PC2 in the attached pic is shown to be on VLAN101 (10.10.101.123).  If the Cisco 3750 is connected to a internal port on the fgt, I assume vlan sub interfaces are also configured under that interface In (on the fgt) or I am missing something?   

    rwpatterson
    New Member
    March 4, 2020

    The interface between the Fortigate and the access switch needs to be a trunk unless you are routing on the access switch (which you are not since the IP subnet appears on multiple interfaces). That trunk will pass traffic on all attached VLANs between the switch and the Fortigate. You would then set up policies on the Fortigate allowing what you need. Alternatively, you could add another access port between the switch and the Fortigate with VLAN 101 passing across it.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!