Skip to main content
filu
New Member
July 24, 2019
Question

Problem with Policy

  • July 24, 2019
  • 1 reply
  • 1981 views

Hello, 

 

I have two networks connected to port1 and port 16 on my FG100. I want connect from Port1 to Port16 . 

I can't ping any address in this network. 

 

config of my port 16 

edit "port16"
--More-- set vdom "root"
--More-- set ip 172.100.x.2 255.255.255.0
--More-- set allowaccess ping https http fgfm capwap
--More-- set type physical
--More-- set alias "MGMT_LAB"
--More-- set device-identification enable
--More-- set snmp-index 4
--More-- next

 

config my port 1

 edit "port1"
--More-- set vdom "root"
--More-- set ip 172.17.x.1 255.255.255.0
--More-- set allowaccess ping https ssh snmp
--More-- set type physical
--More-- set netflow-sampler both
--More-- set alias " LAN"
--More-- set device-identification enable
--More-- set device-identification-active-scan enable
--More-- set snmp-index 11
--More-- set secondary-IP enable
--More-- config secondaryip
--More-- edit 1
--More-- 
--More-- set allowaccess ping
--More-- next
--More-- end

 

config of my policy 

 

edit 40
--More-- set name "MGMTto LAB"
--More-- set uuid 48e6f806-ad20-51e9-08e5-b0363071ad14
--More-- set srcintf "port1"
--More-- set dstintf "port16"
--More-- set srcaddr "LAN 172.16.0.0"
--More-- set dstaddr "all"
--More-- set action accept
--More-- set schedule "always"
--More-- set service "ALL"
--More-- set logtraffic all
--More-- set timeout-send-rst enable
--More-- next

Log for this policy 

 

Date07/23/2019Time15:23:32Duration75sSession ID37486893Virtual Domainroot

 

SourceIP172.16.0.61Country/RegionReservedPrimary MACfxxxSource Interfaceport1Host NamexxxDevice TypeWindows PCOS NameWindows MEUnauthenticated Userxxx$Unauthenticated User SourcekerberosUser xxx$

 

DestinationIP172.101.0.1Host NamexxxCountry/RegionUnited StatesDestination Interfaceport16

 

ApplicationApplication NamePINGCategoryunscannedProtocolicmpServicePING

 

DataReceived Bytes0 BReceived Packets0Sent Bytes240 BSent Packets4

 

ActionActionAcceptPolicy40Policy UUID48e6f806-ad20-51e9-08e5-b0363071ad14Policy Typepolicy

 

SecurityLevel 

 

OtherSource Interface RoleundefinedLog ID13byod_nameskypewawaProtocol Number1roll64317byod_devicewindows-pcLog event original timestamp1563888212Destination Interface Roleundefineddstcountry_codeUSSource Server0Sub TypeforwardSecurity Events[]

 

Should I configure some else ? 

    1 reply

    orani
    New Member
    July 24, 2019

    1. you source address at the policy is not part of the source interface.

    2. the source address is a network address not a host address.

    3. you might need to configure also the reverse policy

    4. at the policy config you say port 1 to port 16 (lab to mgmt) but you named the policy mgmt to lab. (this is not misconfiguration but it doesnot look right

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!