Question
Fortigate to Palo Alto reachable
Hi team, I'm doing a testing lab in my environment as per attached scenerio Switch having an SVI of subnet 192.168.230.0/24, 10.2.2.0/24 Where my switch is connected on fortigate internal port1 IP (192.168.230.1) using ip 192.168.230.254. And fortigate is connected to Palo Alto using L3 link using internal port 3 IP (10.1.1.2) and same is configure on Palo Alto link connected to fortigate ip (10.1.1.1). Whereas fortigate and palto directly connected L3 link can ping each other. My problem is when I assigned vlan 20 of 10.2.2.0 subnet to my laptop I can reach fortigate L3 link ip 10.1.1.2 but can't reach palto Alto 10.1.1.1 Route on Palo alto To reach 10.2.2.0 next hop 10.1.1.2( fortigate L3 link) Policy Internal zone to internal zone policy is created Eg:- source 10.1.1.1/24 to destination 10.1.1.1/24 Route on fortigate To reach 10.2.2.0 next hop 192.168.230.254( switch directly connected link). Ipv4 policy Internal 1 (192.168.230.0/24) source 10.2.2.0/24 to internal 3 (10.1.1.2/24) destination any and same vice versa is created. Policy route Internal 1 (192.168.230.0/24) source 10.2.2.0/24 forwarding interface internal 3 (10.1.1.2) gateway 10.1.1.1( Palo Alto directly connected link ip) and same vice versa is created. Can anyone please help me what I'm missing here Any help will be appreciated. Regards, Vishal
