Skip to main content
svm
New Member
October 3, 2013
Question

Fortigate 100D

  • October 3, 2013
  • 15 replies
  • 24166 views
hello all, i haave this setup with the fortigate 100D: my question is: 1. what configuration will fit my netwotk setup? will i do it in transparent mode or route mode? can i do a basic firewall config on it even if it is configured in router or transparent mode? 2. i cannot access the fortinet 100D default ip.. even if i already reset it in factory default setting through cli.. i already have the 192.168.1.2 in my laptop and i cannot ping the 192.168.1.99 which is the fortigate 100D. thanks

    15 replies

    rwpatterson
    New Member
    October 3, 2013
    Go back in through the CLI and check to see if the interface DOES have the correct IP address.
    svm
    svmAuthor
    New Member
    October 3, 2013
    hi sir, i already configured the fortigate 100D. however. my client pc' s cannot access the internet. if i deploy the fortigate 100D as dual wan. can i set the 2 isp as primary?
    rwpatterson
    New Member
    October 3, 2013
    You need to start off walking before you can run. What' s the browsing status for one connection? Does it work? How far does a packet get before it dies? How much troubleshooting has been done? Yes, you can set either connection up as primary, but if your not browsing yet, what difference does it make?
    svm
    svmAuthor
    New Member
    October 5, 2013
    the browsing status for one connection is that..WAN 1 if my laptop is connected ditectly to the firewall. i can access to goggle. how ever if i connect the distribution switch to the firewall i cannot access the internet
    Fullmoon
    New Member
    October 5, 2013
    see to it NAT was enabled in your firewall policy from Internal-->WAN Interface
    svm
    svmAuthor
    New Member
    October 5, 2013
    hi fullmoon, i have enable NAT on my firewall
    svm
    svmAuthor
    New Member
    October 18, 2013
    hi all, i have configured this fortigate 100D. i directed my laptop to one of its port then i can access anything on the internet. how ever if i connect my switch to the fortinet port. my pc is blocked to any sites and has this error: pls help . thanks
    Dave_Hall
    New Member
    October 18, 2013
    Your attached pic shows you have FortiGuard web filtering enabled on one of the firewall policies, but the 100D can not contact/reach the FortiGuard servers. Make sure the 100D' s internal DNS setting is configured with a proper DNS server IP addresses (System/Network/DNS/). Fortigate devices need a fully functional DNS setting for FortiGuard services to work and also a valid subscription. If the 200D has both, you can force the Fortigate to reestablish a connection to the FortiGuard servers by going to /System/Config/FortiGuard/AntiVirus and IPS Options then clicking on Update Now. After this, click on the " Test Availability" under the " ...Web Filtering and Email Filtering Options" . This is for 4.0 MR 3 firmware.
    svm
    svmAuthor
    New Member
    October 19, 2013
    hi sir, thanks for your reply.. regarding the error which i post lately. i come up to this solution, then i can access everything on the internet.
    svm
    svmAuthor
    New Member
    October 19, 2013
    how ever.. i have a problem: 1. if i try to create wan 2 for dual wan, the status for both DHCP and PPPoE fails
    svm
    svmAuthor
    New Member
    October 19, 2013
    and i also have this problem:
    emnoc
    New Member
    October 19, 2013
    Take rwpatterson advice walk b4 running. Now in your dual wan let' s work on that 1st. Are these interfaces connected to your provider via static dhcp or pppoe since you mention the later 2? if it' s via DHCP and PPPoE and your retrieving the default-gateway from the provider what does your route table looking from the routing monitor? If your static addressing these interfaces ( more preferred setup imho ) than once again do you have the correct addresses? What does your route table look like from the monitor. next can you ping the gateways from the fortinet directly ( go to the console ' execute ping x.x.x.x ' where x.x.x.x is your next-hop-gateways ) Get your dual wan setup 1st b4 trying to enable any profiles with webfiltering.