Skip to main content
jd653687
Visitor III
August 26, 2016
Solved

Fortigate 100D V 5.4.1. Cannot ping vlan from lan

  • August 26, 2016
  • 4 replies
  • 11804 views

Hi,

Just replaced my old firewall (Zywall) with a Fortigate 100D

On the Zywall there were 2 vlans 6 and 99

I rebuild this on the Fortigate. Connected the same cabeling to the fortigate but the vlans are not working.

Lan port 1 is connected to a HP switch and on the switch vlan 6 and vlan 99 are tagged on this port (this was already set)

My question is why is there no traffic between the fortigate and the lan.

Vlan6 Type is Vlan, interface is lan, id is 6. ping is enabled. DHCP is also enabled. ip is 192.168.101.1

Vlan99 Type is Vlan, interface is lan, id is 99. ping is enabled. DHCP is also enabled. ip is 19268.99.254

lan itself is 192.168.1.1

have a policy from vlan6 and vlan99 to Internet and a policy from vlan6 to vlan99 visaversa.

Any why i cannot ping from internal netwerkserver to 192.168.101.1?

    Best answer by MikePruett
    [ul]
  • policies must exist for each subnet to talk to the other
  • vlans need to be built off the physical port connecting the switch
  • Ensure devices on the vlan can ping the gateway (x.x.x.1)...please note you will need PING enabled on the VLAN interface....
  • If you can ping the gateway chances are the policy is the issue[/ul]

    If you can snag us a snapshot of the configuration on both devices we can provide better help

  • 4 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    August 26, 2016

    You need to have a set of policies to allow access each other, unless you put all of them in a same zone and allowed intrazone access. They are individual interfaces policy-wise.

    tanr
    New Member
    August 27, 2016

    To clarify your setup.

     

    FGT Interface 1 is connected to the HP switch on a port that allows vlan 6 and vlan 99 tagged packets.

     

    The switch was already set up and working with the Zywall previously.

     

    You said that vlan6 "interface is lan".  Did you mean that the this vlan interface has the role of LAN?  Or that it is parented off an physical interface port named "lan"?  Or that it is parented off the "lan" interface object which is actually a virtual hardware switch (shows Type: Hardware Switch) on the FGT 100D?  Or parented off a physical port which is a member of a zone called "lan"?  And if there are zones, if they allow intrazone access?...     Too many possibilities here I think, so the need to clarify.

     

    Can you ping the FGT vlan6 interface (10.100.101.1) from another device on vlan6 and in the same subnet successfully?

     

    After clarifying all that, if you can let us know which FortiOS version (5.2x, 5.4x) you're running, and then show the associated routes and security policies, that should hopefully be enough to help.

    MikePruett
    New Member
    August 28, 2016
    [ul]
  • policies must exist for each subnet to talk to the other
  • vlans need to be built off the physical port connecting the switch
  • Ensure devices on the vlan can ping the gateway (x.x.x.1)...please note you will need PING enabled on the VLAN interface....
  • If you can ping the gateway chances are the policy is the issue[/ul]

    If you can snag us a snapshot of the configuration on both devices we can provide better help

  • Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!