Having issues setting a new pair of 200D
Hi
Very strange issue that kept us all day on it with no fix so far.
A few months ago, we had a couple of Checkpoint firewalls which were due to be replaced with 2 x 200D.
The 2 200D were setup in HA, we assigned them with one of our spare external IP address, plug them onto the external routers, and everything worked. We were able to migrate all the VPN tunnels from the Checkpoint to Fortigate, and then at some stage to remove the Checkpoint firewalls.
Now, we are trying to configure 2 new 200D to be sent to another office. Again, we configured then in HA and assigned them with an available external IP address and plugged to the external routers, but we cannot seem to make them connect to the internet properly. from the CLI, we can hardly ping 8.8.8.8 for example, but some time it works with usually at least 60% packet lost. Trace show that it goes a few hops after the first ISP router, but it gets in trouble after. Not always at the same hop.
We setup traffic from lan to internet rules, but whilst the logs in the Fortigate shows that it is OK, nothing work.
Looks like a networking issue, but cannot figure out what it could be.
Could it be an issue to have 2 sets of Fortigate on the same switch, with the same mask? It did not see to be a problem with Checkpoint + Fortigate, but perhaps it is with 2 Fortigate?
Unless, someone else has an idea?
Also, does the MGNT port needs to be connected to the internet? For this new office, there are no specific Vlan for Management.
We thought we would just connect a laptop with 192.168.1.1 to configure it, and leave it empty, once the firewalls are shipped to the remote office, but we wonder if it is also one reason it cannot connect to the internet (to get the licences for example).
Tried to setup the MGNT port with an IP address from the LAN port subnet, but it was not allowed.
All this is very confusing. Any ideas would be greatly welcome!
Cheers
