Local traffic - ICMP workaround
Hi Guys,
There was a weird situation where I applied a workaround to fix for now. Just wanted to know if there is any other good solution I can deploy in my environment.
Issue: Users were unable to ping the default gateway (setup on Fortigate) though the interface had PING enabled. After analyzing the logs, I found that the FG was dropping off the packet considering it to be high threat. The issue seems to be the admin profile I had setup on the device. There were only 2 subnets which were defined as protected subnet. I guess the issue was the Fortigate considering only the management traffic trusted only from the defined protected subnet and rest all as untrusted, so it was dropping packets for untrsuted network even when they were connected directly to the Fortigate.
Workaround: I created a test profile with no access and applied it on a test user profile. After this, the FG interface started responding.
So, just wanted to know if there is any CLI command where I can defined PING to be allowed from any network for the PING enabled interface?
Thanks!
Sandeep Jha
