Skip to main content
Vatsal_shah
Visitor III
June 14, 2025
Solved

Inferface is up still cant ping from outside

  • June 14, 2025
  • 5 replies
  • 4964 views

I'm currently setting up a FortiGate firewall and facing a strange issue. The FortiGate WAN interface is directly connected to my ISP router. 

From the FortiGate, I can ping the ISP gateway successfully.
However, from the ISP router side (or any host behind it), I cannot ping the FortiGate IP.

Here’s what I’ve checked so far:

  • Ping is enabled on the WAN interface (set allowaccess ping is configured).

  • The interface is up, IP is correctly assigned, and the cable is physically connected.

  • No local-in policy is blocking ICMP.

  • No trusted hosts are configured under the admin settings.

  • Subnet and default routes appear correct.

and when I connect that ips wire to my laptop it can get the internet access and able to ping my ip from outside network.Screenshot 2025-06-15 033932.png

Best answer by sjoshi

AHM_MANINAGAR_MNG # get router info routing-table details 103.240.162.91

Routing table for VRF=0
Routing entry for 0.0.0.0/0
Known via "static", distance 1, metric 0, best
vrf 0 185.75.142.113, via lan2 inactive
* vrf 0 43.250.164.190, via wan

If you see above output your active default route is only available via wan but you are pinging lan2 IP address and hence reverse path is failing
You are not able to ping lan2 IP because default route shows inactive via lan2. It could be because of sdwan perf sla down for lan2

5 replies

funkylicious
SuperUser
SuperUser
June 15, 2025

i see that you have 2 public ip/wan interfaces.

if you didnt configure sdwan or ecmp/asymmetric routing, then that might be the issue.

"jack of all trades, master of none"
Vatsal_shah
Visitor III
June 15, 2025

I have done sd wan

funkylicious
SuperUser
SuperUser
June 15, 2025

its time for some sniffer or debug captures while trying to ping the interface/ip and lets see what really happens to the packets.

"jack of all trades, master of none"
sjoshi
Staff
Staff
June 15, 2025

Hi,

 

Have you tried connecting a laptop directly on the fortigate wan port and see if that works.

Is arp entry coming correctly?

 

Try to ping again from the ISP end towards FGT IP and take a pcap to see if the traffic is reaching the FGT

diag sniff packet any 'host x.x.x.x' 4 0 l >> where x.x.x.x is the FGT IP

Thanks, Salon
Vatsal_shah
Visitor III
June 15, 2025

I tried directly connecting my laptop to firewall A port and then i check my laptop ipconfig I got all my ip and gateway proper and try to ping with different laptop and pc from that local subnet I can ping  that IP and gateway to of that ISP but when I plug back the cable to firewall I can ping only to gateway, but can't ping interface ip.

sjoshi
Staff
Staff
June 15, 2025

I guess taking packet capture will give clarity.

Along you capture take a debug flow

https://docs.fortinet.com/document/fortigate/7.6.3/administration-guide/54688/debugging-the-packet-flow

 

Take this output while pinging FGT IP

Thanks, Salon
Vatsal_shah
Visitor III
June 16, 2025

and i am not getting the arp too while using get sys arp command

 

Screenshot 2025-06-16 174806.png

sw2090
SuperUser
SuperUser
June 16, 2025

probably do some flow debug to see packet flow?

 

diag debug ena

diag debug flow filter clear

diag debug flow filter <filter>

diag debug flow trace start <numberofpackets>

 

then generate some traffic to see what happens to it.

Vatsal_shah
Visitor III
June 17, 2025

This is the output i get

AHM_MANINAGAR_MNG # diag debug enable

AHM_MANINAGAR_MNG # diag debug flow filter clear

AHM_MANINAGAR_MNG # diag debug flow filter daddr 182.75.142.114

AHM_MANINAGAR_MNG # diag debug flow trace start
<xxx> Repeat number.

AHM_MANINAGAR_MNG # diag debug flow trace start 100

AHM_MANINAGAR_MNG # 2025-06-16 20:57:49 id=65308 trace_id=23 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103
.240.162.91:21479->182.75.142.114:2048) tun_id=0.0.0.0 from lan2. type=8, code=0, id=21479, seq=34500."
2025-06-16 20:57:49 id=65308 trace_id=23 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a13"
2025-06-16 20:57:49 id=65308 trace_id=23 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:57:49 id=65308 trace_id=23 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:57:52 id=65308 trace_id=24 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103.240.162.91:21479->1
82.75.142.114:2048) tun_id=0.0.0.0 from lan2. type=8, code=0, id=21479, seq=34548."
2025-06-16 20:57:52 id=65308 trace_id=24 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a18"
2025-06-16 20:57:52 id=65308 trace_id=24 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:57:52 id=65308 trace_id=24 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:57:53 id=65308 trace_id=25 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=6, 95.214.53.196:55229->18
2.75.142.114:16379) tun_id=0.0.0.0 from lan2. flag [S], seq 2576057558, ack 0, win 65535"
2025-06-16 20:57:53 id=65308 trace_id=25 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a1b"
2025-06-16 20:57:53 id=65308 trace_id=25 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:57:53 id=65308 trace_id=25 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:57:54 id=65308 trace_id=26 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=6, 188.166.234.65:47861->1
82.75.142.114:3326) tun_id=0.0.0.0 from lan2. flag [S], seq 2346924458, ack 0, win 1024"
2025-06-16 20:57:54 id=65308 trace_id=26 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a1c"
2025-06-16 20:57:54 id=65308 trace_id=26 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:57:54 id=65308 trace_id=26 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:57:55 id=65308 trace_id=27 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103.240.162.91:21479->1
82.75.142.114:2048) tun_id=0.0.0.0 from lan2. type=8, code=0, id=21479, seq=34596."
2025-06-16 20:57:55 id=65308 trace_id=27 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a1d"
2025-06-16 20:57:55 id=65308 trace_id=27 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:57:55 id=65308 trace_id=27 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:57:55 id=65308 trace_id=28 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=6, 149.50.106.170:45708->1
82.75.142.114:2345) tun_id=0.0.0.0 from lan2. flag [S], seq 3174029474, ack 0, win 65535"
2025-06-16 20:57:55 id=65308 trace_id=28 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a20"
2025-06-16 20:57:55 id=65308 trace_id=28 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:57:55 id=65308 trace_id=28 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:57:58 id=65308 trace_id=29 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103.240.162.91:21479->1
82.75.142.114:2048) tun_id=0.0.0.0 from lan2. type=8, code=0, id=21479, seq=34644."
2025-06-16 20:57:58 id=65308 trace_id=29 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a21"
2025-06-16 20:57:58 id=65308 trace_id=29 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:57:58 id=65308 trace_id=29 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:58:01 id=65308 trace_id=30 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103.240.162.91:21479->1
82.75.142.114:2048) tun_id=0.0.0.0 from lan2. type=8, code=0, id=21479, seq=34692."
2025-06-16 20:58:01 id=65308 trace_id=30 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a26"
2025-06-16 20:58:01 id=65308 trace_id=30 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:58:01 id=65308 trace_id=30 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:58:04 id=65308 trace_id=31 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103.240.162.91:21479->1
82.75.142.114:2048) tun_id=0.0.0.0 from lan2. type=8, code=0, id=21479, seq=34740."
2025-06-16 20:58:04 id=65308 trace_id=31 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a2e"
2025-06-16 20:58:04 id=65308 trace_id=31 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:58:04 id=65308 trace_id=31 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:58:07 id=65308 trace_id=32 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103.240.162.91:21479->1
82.75.142.114:2048) tun_id=0.0.0.0 from lan2. type=8, code=0, id=21479, seq=34788."
2025-06-16 20:58:07 id=65308 trace_id=32 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a35"
2025-06-16 20:58:07 id=65308 trace_id=32 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:58:07 id=65308 trace_id=32 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:58:10 id=65308 trace_id=33 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103.240.162.91:21479->1
82.75.142.114:2048) tun_id=0.0.0.0 from lan2. type=8, code=0, id=21479, seq=34836."
2025-06-16 20:58:10 id=65308 trace_id=33 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a3a"
2025-06-16 20:58:10 id=65308 trace_id=33 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:58:10 id=65308 trace_id=33 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:58:13 id=65308 trace_id=34 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103.240.162.91:21479->1
82.75.142.114:2048) tun_id=0.0.0.0 from lan2. type=8, code=0, id=21479, seq=34884."
2025-06-16 20:58:13 id=65308 trace_id=34 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a48"
2025-06-16 20:58:13 id=65308 trace_id=34 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:58:13 id=65308 trace_id=34 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:58:15 id=65308 trace_id=35 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103.19.134.226:1->182.7
5.142.114:2048) tun_id=0.0.0.0 from lan2. type=8, code=0, id=1, seq=115."
2025-06-16 20:58:15 id=65308 trace_id=35 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a51"
2025-06-16 20:58:15 id=65308 trace_id=35 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:58:15 id=65308 trace_id=35 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:58:16 id=65308 trace_id=36 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103.240.162.91:21479->1
82.75.142.114:2048) tun_id=0.0.0.0 from lan2. type=8, code=0, id=21479, seq=34932."
2025-06-16 20:58:16 id=65308 trace_id=36 func=init_ip_session_common line=5995 msg="allocate a new session-000f0a53"
2025-06-16 20:58:16 id=65308 trace_id=36 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop"
2025-06-16 20:58:16 id=65308 trace_id=36 func=ip_session_handle_no_dst line=6081 msg="trace"
2025-06-16 20:58:19 id=65308 trace_id=37 func=print_pkt_detail line=5811 msg="vd-root:0 received a packet(proto=1, 103.240.162.91:21479->1

sjoshi
Staff
Staff
June 17, 2025

Hi,

 

From the pcap and debug flow I can see that traffic is received on the FGT but it is getting drop due to reverse path failure

2025-06-16 20:57:58 id=65308 trace_id=29 func=ip_route_input_slow line=2267 msg="reverse path check fail, drop 

 

Share below output

get router info routing-table details 103.240.162.91

get router info routing-table all

 

 

 

Thanks, Salon
Vatsal_shah
Visitor III
June 17, 2025

hey guys issue has been solved the gateway ip was inserted wrong. thanks for all of your support.