Skip to main content
sirride
New Member
September 24, 2019
Solved

Ping within subnet

  • September 24, 2019
  • 2 replies
  • 6810 views

I have a FortiGate 50E with a FortiSwitch 124E-FPOE 

I have a client subnet on the switch with my clients, a NAS and a printer

In addition, i have a vlan for VoIP and IPSec VPN

I can ping across all all Subnets, but not within the client subnet. e.g. client to printer

I can ping from outside the client subnet (from Wlan, from IPSec etc) to the NAS and the printer

 

I can ping from my client subnet to all other subnets

But I can not ping from the client subnet to other systems in the client subnet.

What do i need to change?

    Best answer by Seppel

    could it be possible you have enabled Access VLAN on your Client VLAN?

    2 replies

    yunus56
    New Member
    September 24, 2019

    Hello

     

    Please check your policies and pbr rules on fortigate. it seems ttaht there is problem is regarding Forti-switch

    Seppel
    SeppelAnswer
    New Member
    September 24, 2019

    could it be possible you have enabled Access VLAN on your Client VLAN?

    sirride
    sirrideAuthor
    New Member
    September 24, 2019

    I don't really understand:

    The Clients are in the same Subnet, so there wont be any routings / policies?

    sw2090
    SuperUser
    SuperUser
    September 24, 2019

    that's the way I know it. Client to Client in the same subnet does not even reach the firewall because the client has a route for that subnet as it has an interface in it. It does not matter if this is a vlan interface or a physical one.

    Only traffic that leaves the client's subnet will hit the default gw. 

    So I would point to your (Forti)Switch. Maybe it has somethink linke port isolation or similar that prevents ne port from reaching annother (Except from the uplink to the FGT).

    sirride
    sirrideAuthor
    New Member
    September 25, 2019

     

    I've now disabled "access VLAN" and now it works

     

    Many thanks!