Question
FSAE not working from Virtual Cluster 2
Hello ! We have two 620B' s (OS 4 MR1 patch 3) running in HA and 2 Virtual Clusters (Active-passive). Virtual Cluster 1 is primary for 2 VDOMs + the root VDOM while Virtual Cluster 2 is running 2 VDOMs. In other words we have 3 VDOMs running on physical box #1 (VC1) and 2 VDOMs running on Box #2 (VC2) The strange thing is that from the VDOMs in VC1, FSAE is working fine. From VC2 I can connect to FSAE (The FortiGate unit shows up in " Show Service Status" in FSAE Collector Agent Configuration), but FortiGate can' t read any group information from FSAE. When I try to ping or traceroute servers from the CLI in VC1 I get replies, but from VC2 there' s no replies even when pinging servers with VC2 as the gateway. When doing a traceroute from VC2 I get an error message: # exec traceroute 10.231.10.5 traceroute to 10.231.10.5 (10.231.10.5), 32 hops max, 72 byte packets 1 traceroute: sendto: Operation not permitted traceroute: wrote 10.231.10.5 72 chars, ret=-1 *traceroute: sendto: Operation not permitted traceroute: wrote 10.231.10.5 72 chars, ret=-1 Anybody got any ideas about what might be causing this ? regards, PÃ¥l Gjerde, Norway
