Skip to main content
jd653687
Visitor III
September 5, 2016
Solved

Traffic blocked by implicit Deny

  • September 5, 2016
  • 13 replies
  • 27197 views

My fortigate 100d is not forward traffic between Guestlan and lan.

Guestlan is on a seperate lan.

Wan adresses are 200.200.200.2 255.255.255.240

One webserver is on 200.200.200.3 and traffic is going fine. From the internet as from the guestnetwerk

the second webserver is on 200.200.200.2

From the internet this website is accessable. But when we try to acces the website from the guestnewerk it is not accessable. When we look at the log and report we see it is getting in the Implicit Deny rule.

 

The guest network is 192.168.1.1 and external adres is 200.200.200.13. We have internet acces and eveything is working fine.

When I put the webserver from 200.200.200.2 to 200.200.200.4 it is working fine. When I change this back to 200.200.200.2 it stops working. Is this a bug because we use the first address in the range.

 

https on the webinterface is not enabled.

System settings https port 443 is changed to 8443 for Administration logon.

 

Please assist

    Best answer by ede_pfau

    There's more to a hairpin VIP, read here: http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD36202

    But I agree, @emnoc's got it.

    13 replies

    jd653687
    jd653687Author
    Visitor III
    September 5, 2016

    Hi Br,

    Using VIP for the webserver.

    jd653687
    jd653687Author
    Visitor III
    September 6, 2016

    It is secondary address.

    VIP

    Name HTTPS-VIP

    HTTPS 200.200.200.2 --> 192.168.10.2 (TCP 443--> 443)

    Policy

    Incoming wan1

    Outgoing Lan

    Source All

    Destenation HTTPS-VIP

    Schedule always

    Service HTTPS

    Action Accept

    NAT off

     

    Traces .

     id=20085 trace_id=199 func=print_pkt_detail line=4784 msg="vd-root received a packet(proto=6, 192.168.1.87:55212->200.200.200.2:443) from GuestLan. flag , seq 3301314164, ack 0, win 8192" id=20085 trace_id=199 func=init_ip_session_common line=4935 msg="allocate a new session-00a7e0ff" id=20085 trace_id=199 func=fw_pre_route_handler line=182 msg="VIP-192.168.10.2:443, outdev-unkown" id=20085 trace_id=199 func=__ip_session_run_tuple line=2808 msg="DNAT 200.200.200.2:443->192.168.10.2:443" id=20085 trace_id=199 func=vf_ip_route_input_common line=2584 msg="find a route: flag=04000000 gw-192.168.10.2 via lan" id=20085 trace_id=199 func=fw_forward_handler line=691 msg="Allowed by Policy-10:" id=20085 trace_id=199 func=ids_receive line=253 msg="send to ips" id=20085 trace_id=200 func=print_pkt_detail line=4784 msg="vd-root received a packet(proto=6, 192.168.10.2:443->192.168.1.87:55212) from lan. flag [S.], seq 1870954775, ack 3301314165, win 8192" id=20085 trace_id=200 func=resolve_ip_tuple_fast line=4848 msg="Find an existing session, id-00a7e0ff, reply direction" id=20085 trace_id=200 func=vf_ip_route_input_common line=2584 msg="find a route: flag=04000000 gw-192.168.1.87 via GuestLan" id=20085 trace_id=200 func=ids_receive line=253 msg="send to ips" id=20085 trace_id=200 func=__ip_session_run_tuple line=2794 msg="SNAT 192.168.10.2->200.200.200.2:443"

    jd653687
    jd653687Author
    Visitor III
    September 6, 2016

    200.200.200.4 has no VIP only outgoing traffic, not inbound.

    This seems the problem :

    func=__ip_session_run_tuple line=2808 msg="DNAT 200.200.200.2:443->192.168.10.2:443"

    func=fw_forward_dirty_handler line=359 msg="blocked by forwarding policy (Guestlan-> lan), drop"

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.