Skip to main content
Hisoka74
New Member
October 30, 2023
Question

Firewall block icmp ?

  • October 30, 2023
  • 4 replies
  • 3588 views

hello everyone, im just new here and i have i problem with firewall .i setup like that, when i put firewall alone with internet i can access web gui fortinet ,but when i put i after router and config like that ,i can ping each other ,router can ping 8.8.8.8 but firewall not .I dont know what problem with my firewall now,pls help.sorry for m

1.png

4 replies

AEK
SuperUser
SuperUser
October 30, 2023

Hello

Do you want to access firewall GUI from Internet or you just want your firewall to ping Internet?

 

AEK
Hisoka74
Hisoka74Author
New Member
October 30, 2023

thanks for your respond,i want both.

ebilcari
Staff
Staff
October 30, 2023

Starting from your description I guess you have to configure default route on the firewall (next hop 192.168.1.10) and enable NAT on router R1 (or fix the routing from Net). If you want to reach FGT from the internet you have to configure DNAT/port forwarding in the router.

Emirjon
mle2802
Staff
Staff
October 30, 2023

Hi @Hisoka74,
When connected to the R1, on FortiGate, can you do the following command "execute traceroute 8.8.8.8" and see is the next hop is R1? If yes then the traffic must be drop on R1 and you may need to run debug to see why they are dropping.

Regards,
Minh

smayank
Staff
Staff
October 31, 2023

Hello

As I can see you are able to access internet directly but not after connecting router.
For this you need to enable internet on router and need to give static route(Gateway will be router interface ip )address.
Regards
Mayank Sharma

Hisoka74
Hisoka74Author
New Member
November 1, 2023

thanks for your respond,you mean enable ip nat outside 192.168.10.1 and give static route right