Skip to main content
kcerb
New Member
September 26, 2008
Question

second IP on internal interface - problem

  • September 26, 2008
  • 19 replies
  • 11530 views
Hello, I added second IP address on internal interface (FortiGate 100A). I have also enabled Administrative Access - PING. The main IP address on this interface is 10.0.0.1/24 The second IP address on this interface is now 192.168.0.1/24 On Windows client PC I have main IP address: 10.0.0.23. Now I added additional IP address: 192.168.0.23 on network card properties. Why can`t I ping to 192.168.0.1 ? I have also other PC`s with 192.168.0.x addresses and I can ping to them.

    19 replies

    UkWizard
    New Member
    September 30, 2008
    try your pc with just the one static IP 192.168.0.x and see if that works. This is getting odder by the second, this could be a switch problem, do you have any vlans, trunks or managed switches? or any routers within the infrastructure?
    kcerb
    kcerbAuthor
    New Member
    September 30, 2008
    From test computer (with only one IP address 192.168.0.x with 192.168.0.1 as default gateway) ...
    I just made simple test: I connected notebook with manualy set one IP address (192.168.0.x) straight to FG (other internal port) and it`s the same situation. I should have allow-overlap enabled or disabled?
    rwpatterson
    New Member
    September 30, 2008
    Overlap only matters when you wish to have two interfaces share the same IP range. That does not apply here. Treat both networks as independent. The 10.0.0.x works, now forget it! Work on the 192.168.0.x network. Define the default gateway, and then the rule to permit traffic, etc. Even though they are on the same wire, they won' t talk without an explicit FGT rule allowing it (except for that funky PC with two IP addresses). I think you are confusing yourself.
    kcerb
    kcerbAuthor
    New Member
    September 30, 2008
    I solved the problem. 1. I could not execute PING from 192.168.0.x subnet to second FG IP address because in Trusted Hosts (administrator settings) I had only 10.0.0.0/24. Because PING is treated as administrative access, it acted only with subnet 10.0.0.0/24. 2. Internet connection from net 192.168.0. x did not act because I didn' t have DNS server in this subnet (I forgot about this). I also didn' t have enabled " Enable DNS forwarding from: internal" option in Networking options. I' m very grateful for Your help, thank you very much.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.