Created on 11-05-2009 05:54 AM Edited on 07-06-2022 08:57 AM By Anonymous
Description
Under some conditions, issues in delivery of IP packets to their destination can occur. ICMP error messages are used to feedback the source with the origin of the problem encountered.
This article explains the FortiGate system behavior with regards to various ICMP message types.
Scope
Solution
The general behavior of the FortiGate firewall policy is the following :
.10 .106 .106 .110 [ PC1 ] ------ internal---- [ FortiGate ] ---- wan1----- [ Router1 ] [ PC2 ] .132 10.160.0.0/23 192.168.182.0/23 |
config firewall policy edit 1 set srcintf "internal" set dstintf "wan1" set srcaddr "all" set dstaddr "all" set action accept set schedule "always" set service "TFTP" next end |
3.677808 internal in 10.160.0.10.1262 -> 192.168.182.132.69: udp 20 3.677960 wan1 out 10.160.0.10.1262 -> 192.168.182.132.69: udp 20 3.678465 wan1 in 192.168.182.132 -> 10.160.0.10: icmp: 192.168.182.132 udp port 69 unreachable 3.678519 internal out 192.168.182.132 -> 10.160.0.10: icmp: 192.168.182.132 udp port 69 unreachable |
2.234765 internal in 10.160.0.10.1287 -> 10.2.2.1.69: udp 20 2.234908 wan1 out 10.160.0.10.1287 -> 10.2.2.1.69: udp 20 2.235164 wan1 in 10.1.0.1 -> 10.160.0.10: icmp: net 10.2.2.1 unreachable 2.235208 internal out 10.1.0.1 -> 10.160.0.10: icmp: net 10.2.2.1 unreachable |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.