Skip to main content
Daniel_Aguilar
New Member
June 9, 2020
Question

FG 80E Issues with static routing

  • June 9, 2020
  • 4 replies
  • 4373 views

Hello, I'm trying to configure my FortiGate 80E as a router with static routing, but I'm having issues that I can't understand.

 

This is my current config:

Port4 has IP 172.16.0.1/255.255.255.0

Port2 has IP 172.16.1.1/255.255.255.0

In port2 I have a host with 172.16.1.2 and in port4 one host with 172.16.0.2.

From 172.16.0.2 I have succesful pings with 172.16.0.1

and 

From 172.16.1.2 I have succesful pings with 172.16.1.1

 

But I can't connect each other. I can't ping from 172.16.1.2 to 172.16.0.2 or 172.16.0.1 and I don't know why. Both subnets are directly connected to FortiGate

 

    4 replies

    emnoc
    New Member
    June 9, 2020

    The "diag debug flow" is your friend. I would run that and verify the 1> fwpolicy 2> if nat is not not talking place 3> the route

     

    Sounds like fwpolicy or lack of proper default-gateway on the two hosts. You can do a ping and monitor form the cli also to see what is happen

     

       diag sniffer packet any "host 172.16.1.2 and 172.16.0.2" 4

     

    Ken Felix

     

     

     

     

    James_G
    New Member
    June 9, 2020

    Have you setup policies to allow traffic?

    sw2090
    SuperUser
    SuperUser
    June 10, 2020

    This is obviously not a routing issue on the Fortigate. The FGt does have routes because it has interfaces in that subnets.

     

    This can have the following reasons:

     - the PCs don't have the FGt als default gw - in this case THEY need to have static routes

     - you don't have a policy or policies to alow the trafic between those two ports and subnets in all required directions - in this case you will always match Policy #0 which means implicit deny. This is default behaviour of all FGT.

     

    As Ken wrote you could check this on the FGT with diag debug flow. If the traffic reaches the FGT you will see what happens to it on the FGT in Flow Debug.

     

    VitaliyN
    New Member
    June 10, 2020

    Hi!

    If i'm right, you need 2 firewall policies: from port4 source 172.16.0.0/24 to port2 destination 172.16.1.0/24

    and vise versa.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.