I cannot access the Fortigate 200F MGMT port IP address
I have a Fortinet 200F hardware controller setup in an High Availability Cluster. The version is v7.2.8 build1639 (Mature).
Background:
- The dedicated MGMT Interface IP address is X.X.30.254. IP address.
- The FortiGate LAN interface is using a X.X.99.X IP address.
- My workstation is using X.X.210.X IP address.
Problem Description:
I can login to the FortiGate FW Web interface just fine using the assigned LAN IP Address (X.X.99.X) from my workstation (X.X.210.X) ; but, I cannot get a web page or ping the IP address assigned to the FortiGate MGMT Interface (X.X.30.354) from my workstation.
I can access and ping other devices on the same X.X.30.X network from my workstation; hence the problem is specific to the X.X.30.254 Interface. By the way other devices on the same subnet (X.X.210.X) have the same problem with the FortiGate MGMT Interface address (X.X.30.254).
I have set the following configuration on the FortiGate "MGMT physical Interface"

My workstation is on 1 of the 3 trusted host subnets that I have configured under the Dedicated port section. We can continue to work with the FortiGate Web UI by using the LAN Interface IP address (X.X.99.X) but I want to understand how to get the MGMT Interface IP address to be accessible from our corporate network.
Question1: Can we use both the LAN Interface and the MGMT Interface to access the web internface?
Question2: Is the MGMT Interface supposed to only be used for Out of Band communicaiton? Such as not to access from the corporate network? That just sounds silly to me after typing this question.
I just discovered that if I setup a laptop on the X.X.30.X network and I browse to the MGMT IP Interface Address (X.X.30.254) then that works. Hence the problem is specific with the X.X.210.X network.
If I try to ping the FG - MGMT IP address from the Default gateway Router there are ping replies to the MGMT IP address. Equally important, I can ping other devices from the router and from my workstation that are also on the same subnet (X.X.30.X ). I just cannot access the Fortigate MGMT IP Address from the corporate network. Hence the problem appears to be specific to the FortiGate MGT Interface Ip address.
Since the Dedicated Port setting is enabled I do not see the MGMT Interface as an option for Firewall policies.
When I run a packet capture from my workstation I just see packets being sent from my workstation being sent to the MGMT Interface IP address; but, no replies back. No ECHO Ping replies or TCP - ACK packets from the Fortigate.
Ideas, suggestions.... ?
