Skip to main content
admpius
New Member
May 13, 2024
Solved

Fortigate behavior changes without apparent reason.

  • May 13, 2024
  • 3 replies
  • 1718 views

Hello everyone. In our infrastructure, we have a Fortigate 100f. Situation: we are replacing our main switches. I have attached an image for you to see the changes. Basically, we want to remove core-1 and core-2 switches and will keep core-3 and core-4. Currently, everything has been migrated except for VLAN 1, where the firewall and the network communications of the switches are located. The only change I really see here is in MAC addresses since we are configuring the VRRP group in the new cores. That said, when we move VLAN 1 to cores 3 and 4 to finally shut down cores 1 and 2, everything works perfectly except for the services we have in the DMZ of our Fortigate. The question I have is, what could be changing if currently everything is working including the DMZ, and when we make the switch, everything works except the Fortigate's DMZ. Basically, the behavior of the Fortigate is that it sends the traffic, which it is currently correctly sending to the LAN, to another interface or towards the internet. I would appreciate some help on this, and if you need more details, please do not hesitate to ask.

 

Best answer by AlexC-FTNT

"Basically, the behavior of the Fortigate is that it sends the traffic, which it is currently correctly sending to the LAN, to another interface or towards the internet."
>> routing issue. Check the routing table related to the destination IP:
get router info routing table all
get router info routing table detail DES.TIN.ATION.IP

3 replies

AlexC-FTNT
Staff
Staff
May 13, 2024

"Basically, the behavior of the Fortigate is that it sends the traffic, which it is currently correctly sending to the LAN, to another interface or towards the internet."
>> routing issue. Check the routing table related to the destination IP:
get router info routing table all
get router info routing table detail DES.TIN.ATION.IP

admpius
admpiusAuthor
New Member
May 14, 2024

I understand, but the problem is that we are not making any changes to the routes. The routes have already been moved and are working correctly. Today at 17:00 we will make another attempt. Could you suggest a command to diagnose what the problem might be? In any case, I will also check the routing tables. Thank you.

AlexC-FTNT
Staff
Staff
May 14, 2024

I can only think about the directly connected routes. If the subnet does not appear as directly connected anymore, then FortiGate will use the default route out (wan).

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!