Skip to main content
rayha
New Member
January 8, 2024
Solved

Fortigate 100F Cannot access internet

  • January 8, 2024
  • 2 replies
  • 10149 views

Hi,

     I am new to the fortigae 100F. I am trying to setup my laptop to access the internet. My issue is that from my laptop, i can ping 8.8.8.8 but i cannot surf any of the webpage.

 

   Does anyone have any idea what could be the most possible issue? 

 

   Secondly, i discovered this firewall rule that cannot be deleted. Will this rule does anything?

 

Screenshot 2024-01-08 134944.jpg   Really hope someone can enlighten me, Thanks

 

Best answer by kcheng

Hi @rayha 

 

You laptop need to have access to your DNS server. For example, if you are using 192.0.0.1 and it is hosted internally within your network, you need to ensure that after connecting the laptop behind FortiGate, you are still able to access ping or perform nslookup with the DNS server you configured. If I'm not mistaken, after you configure the DNS and IP manually, the access to the DNS server is not in place, hence you can't resolve to fortinet.com and unable to ping through it.

 

You can also manually change the DNS on your laptop to any of the public DNS Servers such as 8.8.8.8 and 8.8.4.4 to verify if the access is working. If it is, access to your internal DNS server will need to be checked.

2 replies

srajeswaran
Staff
Staff
January 8, 2024

You cannot delete/modify the Implicit Deny policy, this is for the traffic/packets not matching any policies.

Regarding internet access issue, can you make sure the firewall policy is allowing DNS (if you are using external DNS) and HTTP/HTTPS?

Also, please check the forward traffic logs to see if there are any reason for dropping the browsing traffic.

rayha
rayhaAuthor
New Member
January 8, 2024

Hi Suraj,

         Thank for the reply.

         I had only one firewall rule as show below.

         I had choose all for the services.

     

       Screenshot 2024-01-08 134944.jpg

     Just now i use my desktop Whatapps and managed to send out message to other party. 

     But still cannot surf internet.

     I check the forward log and nothing special show up there. 

srajeswaran
Staff
Staff
January 8, 2024

Whats your DNS IP configured? Are you able to resolve domain names?

Can you perform "ping fortinet.com" from command line of your PC and share the result?

 

hhasny
Staff
Staff
January 9, 2024

Hi @rayha ,

Could you take a look at this KB article of step 3 and step 4? Here we can make sure packet is hitting the Fortigate and if Fortigate is forwarding it out.

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connectivity/ta-p/192560

 

regards,