Skip to main content
vidden9999
New Member
May 10, 2018
Question

Fortigate 100E - Cannot access port of IP Wan after upgrading from 5.4 to 5.6

  • May 10, 2018
  • 1 reply
  • 2485 views

Dear all,

I have a public IP of the ISP, using NAT to one IP of DMZ Fortigate 100E.

Example:

Public IP of the ISP: 1.2.3.4 Nat to Internal IP of DMZ port Fortigate 100E 192.168.1.2 (myserver.mydomain.com)

Policy: LAN to WAN1, LAN to DMZ, DMZ to WAN1, WAN1 to DMZ.

When I used firmware 5.4, I was in LAN and ping myserver.mydomain.com (1.2.3.4) OK, and access myserver.mydomain.com:port (ex: myserver.mydomain.com:1000) OK.

But after upgrading to 5.6, I can not ping to my server myserver.mydomain.com and I can not access myserver.mydomain.com:1000.

 

Any help for me?

Best regards and thank a lot.

 

1 reply

Toshi_Esumi
SuperUser
SuperUser
May 10, 2018

What's in "diag debug config-erorr-log read" after the upgrade? If you don't see anything related to DNS setting and policies that might have affected to your pinging, you need to start debugging from DNS resolution then sniffing ping packets.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!