FortiDeceptor
FortiDeceptor provides Deception-based Breach Protection to deceive, expose and eliminate external and internal threats.
melshehaby
Staff
Staff
Article Id 240470
Description

 

This article explains the reasons why the Deployment Network monitors IP and Decoy IP addresses are not reachable from outside if configured with a VLAN tag.

 

Solution

 

There are four probabilities that can cause this issue:

 

1) The issue can be in the hypervisor if VMware version 6.5 or 6.7 is installed, and has an issue with the network adapter so if the VM adapter E1000E changes to E1000, this is supposed to fix the issue if applicable.

 

2) If the hypervisor virtual switch is not supporting or the MAC addresses mapping option is not enabled, it can cause the same issue.

 

FortiDeceptor has multiple VMs, and each one has its own MAC address, so the virtual switch should support the MAC address mapping or spoofing as the communication will be from the same adapter with multiple MAC addresses.

So it would be necessary to enable 'Promiscuous mode' in the virtual switch assigned to the Deployment network port.

 

Also, make sure to follow the below instructions:

https://docs.fortinet.com/document/fortideceptor-private-cloud/4.2.0/vmware-esxi-deployment-guide/19...

 

The below screenshot for this option in VMware:

 

melshehaby_0-1671613912294.png

 

3) If the physical switch port is configured with a VLAN tag, in this case, it is necessary to configure the deployment network with VLAN 0 not with the assigned VLAN.

4) In the case of Hyper-V, make sure that the option 'MAC address spoofing' is enabled. It is located under the advanced option in the network adapter configuration.