Skip to main content
zmag
New Member
October 27, 2010
Question

External access

  • October 27, 2010
  • 16 replies
  • 8425 views
FG620B 4.0 MR2 Patch 1 build 0279 I have a complete config built and ready to be tested in production. I also have a 4 hour tech call that came with the purchase and I would like to use it. In order for this to happen support needs remote access. This device is sitting in a different network so I need to edit a new port for a DSL line and create policies just for access in and browsing. I am using a spare port for a WAN link but I must be missing something. port14 , public ip static, admin access = http, https, ssh, ping It seems to me that just having this interface config with admin access I should be able to ping it, but i can not. I can ping out to any public IP from the cli. If I use that static ip in a browser from the dev (local) network it launches the GUI admin page, but it is not reachable from the outside. I created a VIP and forwarded that to the local interface of the firewall to see if that worked but it didn' t. Still can' t ping the firewall. I have a log in the Analyzer - status = deny source - my production ip destination - my VIP Policy ID- 0 <<<<----- ?? Protocal -1 Subtype - Violation Thanks in advance.

    16 replies

    rwpatterson
    New Member
    October 27, 2010
    This post is a bit confusing... The device is in a different network, but has a public IP? Does that ' different' network reside in the same subnet?? Is the default gateway pointed to the interim router, or is this unit on the edge?
    zmag
    zmagAuthor
    New Member
    October 27, 2010
    Sure, The different network is a mirror image of my production network, so the lan ip scheme is 192.168.40.0/22 (same as my prod net). The firewall ip will remain 192.168.40.100/22 in both the dev net and the prod net. We have a DSL connection for this network, and we have 2 seperate ISPs for my prod net. This unit is currently on the edge, no router in dev and the default route states 0.0.0.0/0.0.0.0 Gateway 151.x.x.x. I just realized that this dsl, which is configured at port14 makes the 3rd WAN link. and I wonder if that is an unacceptable config? Also, for clarity, the 2 networks never connect. If it is true that there can only be 2 WAN ports, than I am going to have to blow up this config as I have about 50 rules and lots of addresses that are bound to my other 2 WAN links.
    rwpatterson
    New Member
    October 27, 2010
    Maybe I need some caffeine... I' m still not on beam here. One unit? 2 units? 3 DSL connections. 2 identical LANs, OK. On how many units? Sorry for the cement brain.. It' s late, tough day here...
    zmag
    zmagAuthor
    New Member
    October 27, 2010
    I guess I will use a different approach of explaining this. My production network has 11 subnets over 7 sites (this includes vlans) I am working on replacing a CheckPoint NGX with a Fortigate 620B HA cluster for production. I configured the FG620 so it would plug into my production net and replace the CheckPoint. This was done in a very small network that we use for dev simply so I could access the firewall and analyzer and test some of the config. The result is that I have a firewall configured with hundreds of addresses, 125 policies, 1 lan port, 1 dmz port, 2 vdoms and 2 wan ports but it is plugged into my dev network. So, once that was done (to the best of my knowlege) I decided I would take advantage of a " free" 4 hour support call from Fortinet as a sanity check of my new config. The problem with that is that Fortinet requires access to the firewall. Since this firewall is configured as if it were in my production network, it is set up to use either of the 2 isp addresses that I have in production. I' ll call them 12.1.2.3 and 14.1.2.3. Those 2 addresses are not available in dev, but i do have a dsl line (126.1.2.3) sitting there that we use for our dev and testing. So i need to connect the FG to the 126.1.2.3 just for internet and remote access so Fortinet support can take a look. My guess is that I can' t have 3 active WAN ports but I am not sure if this is true or not. Sorry about leaving out massive amounts of detail but I thought it would just be confusing. Let me know if this makes more sense.
    rwpatterson
    New Member
    October 27, 2010
    If the two active DSL ports are for load balance, you could move one over for testing.... If they are each assigned different tasks, then you would have to schedule a window for testing. Alternatively, you could change one of the DSL addresses on the test unit to the third line and go with that. It won' t be the correct line, but the functionality will be there, just an IP change and security on the interface. My two cents. By the way: Make sure you enable NAT on the policy going out to the Internet (port 14).
    ede_pfau
    SuperUser
    SuperUser
    October 27, 2010
    Yee-haw, there is nothing wrong with your config. As you have already stated, you can ping any target out there. So the WAN connection is up (which one remains unknown), the routing is OK. My guts tell me it' s a matter of missing permissons. " Policy 0" is the implicit DENY rule, the one that blocks everything after all self-declared policies have been passed. So your traffic has been blocked. There is no limit on " WAN ports" ...all ports can be used for all purposes. So it must be something else. Have you configured " Administrative Hosts" ? That would explain why access from the LAN is permitted and from outside is not. To test whether the WAN config is OK, you could disconnect the 2 other WAN cables and ping an external target from the FG. If that works, routing and policies are correct.
    ede_pfau
    SuperUser
    SuperUser
    October 27, 2010
    @rwpatterson: Mercy on you and let the evening come...I wonder in which timezone you are living. Mine is GMT+1 so _I_ am off-hours now. Nearly laughed my head off when I read your mumblings...I' m not sure if we get a decent support together for the rest of the day.
    rwpatterson
    New Member
    October 27, 2010
    :) In New York, and it' s 10 minutes to quitting time. YES! Our Alcatel switches doing layer 3 routing are kicking me in the seat with intermittent 10 second outages. Totally random, not remotely coincidental with anything. Not traffic, CPU load, memory... It sucks! The thin clients drop every time, and I' m catching s**t from all sides. My most hated question... " Do you know when it' s going to be fixed?" My response? " If I knew the answer to that, you would not be asking me that question!" Groan
    zmag
    zmagAuthor
    New Member
    October 27, 2010
    I guess I have to come to terms with my communication issues (proves my wife right!) There are 3 wan links configured but there is only one plugged in. The other 2 interfaces are configured so they will work when I move this to production. The only one that is plugged in is the DSL for dev.
    Have you configured " Administrative Hosts" ? That would explain why access from the LAN is permitted and from outside is not.
    I haven' t configured administrative hosts, actually haven' t seen that option. I assume that' s a filter for administrative access per interface?
    To test whether the WAN config is OK, you could disconnect the 2 other WAN cables and ping an external target from the FG. If that works, routing and policies are correct.
    It does work. So if there is no limit on wan ports, and this traffic is blocked by the implied DENY rule, I am missing a rule to allow this traffic in. The rule I created states; src int = port14 (dev_dsl) src addr = all dst int =port14 (dev_dsl) dst addr = vip_fg1 service= any action = allow enable NAT = yes Finger crossed that this makes sense.
    rwpatterson
    New Member
    October 27, 2010
    This all depends on your goal. To get Internet access out you need a policy from port x -> port 14, NAT enabled. For them to get into your unit, enable HTTPS and/or SSH on port 14. No VIP required for they only need to get to the management side, not the network. Access inward is on the ' Network > Interface' page. I' m using an older version. It may have moved on your version. I' m not sure.
    I haven' t configured administrative hosts, actually haven' t seen that option. I assume that' s a filter for administrative access per interface?
    In the ' Network -> Administrator' area, this gives the administrator rights when inside the unit. It also tells the FGT what IP subnets each admin is allowed in from. 0.0.0.0/0 is from anywhere.
    zmag
    zmagAuthor
    New Member
    October 27, 2010
    Exactly, My first step was to allow HTTP, HTTPS, SSH and ping on port14 for administrative access. I expected that to work. When it did not (unreachable from an external address) I thought I would create a VIP to see if that would work. It did not, that is where I got hung up. Seems to me that both of the methods should allow access into the FG unit. I' m not sure what to try next as a troubleshooting step.
    ede_pfau
    SuperUser
    SuperUser
    October 27, 2010
    Scrap that policy from port14 to port14, it' s unnecessary. Same for the VIP, please delete the definition, it does things while it exists, arp and such. Disabling the policy won' t do. (For higher security you would deny access to the external port, allow access to the internal port and set up a dialup VPN. But that' s not our case here). Let' s focus on the DSL wan transfer net. You must have a DSL modem in bridge mode there, or a full fledged router. With a briding modem there is nothing to configure other than the credentials in " Network" > " Interfaces" . With a router it' s different. How do you route across it? Routes on the FG and the router for incoming traffic? How do you forward traffic to the FG? Did you open ports? And still, please check the permitted subnets for admin access in " Network" > " Administrator" . There are 3 entries all of which should be showing " 0.0.0.0/0" . I suspect the FG doesn' t know about the router' s IP/subnet and discards the packets for security reasons.
    zmag
    zmagAuthor
    New Member
    October 27, 2010
    I do have the dsl modem in bridge and this dsl line has worked with the prior FG config. I also am able to ping out from the firewall to any public host, so that part works. I will delete the VIP in the morning since it was really just a test and it will not be part of my final build. There is no router in this config, I have the FG as a gateway for my lan and I have a static route in the FG that sends to my external gateway. I will check the permitted subnets for admin access tommorow. I' m having a hard time getting past these basic facts; 1> My inbound traffic is blocked at FG with rule 0, 2> I have a rule that states all hosts on wan port14 can get to vip_(whatever_the_name_is) with any service, any time 3> Using my vip address from the lan does launch the admin gui. I appreciate your help and ideas, who knows, maybe the answer will come to me in a dream.
    zmag
    zmagAuthor
    New Member
    October 28, 2010
    I am able to get in. I did delete the vip and I checked the permitted subnets, which were at default, allow all. I changed the interface ip address to one higher in the subnet and that got me in. My guess is that I have a config issue in my dsl router. Thanks to all for your help.
    rwpatterson
    New Member
    October 28, 2010
    Glad to hear you figured it out. Can you help me with my Alcatels? LOL!
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!