FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
vbandha
Staff
Staff
Article Id 276105
Description This article describes troubleshooting steps if getting a Duplicate IP message or IP conflict log.
Scope v7.0+.
Solution

If getting a Windows event notification that there is an IP conflict, and the Mac address of that is matching with FortiGate, then it may be related to the IP Pool or Virtual IP configuration.

 

windowsipconflict.png


If, for example, an IP Conflict for 192.168.2.1 is shown, then an IP Pool similar to this should exist:

 

1.JPG

 

Here, disable the ARP Reply option and select ‘Ok’. Then a configuration should appear as shown below:

 

2.JPG
The same steps can be applied if a Virtual IP is the cause of the conflict. The external address is 192.168.2.1, so this issue would be present:

 

badvip.PNG

Click on 'Edit in CLI', then set 'arp-reply' to disable:

badvip-arp.PNG

 

This should resolve the IP Conflict. With the ARP reply enabled, FortiGate responds to ARP requests which can cause IP conflict in the environment.

In specific versions of FortiOS, the addresses of IP Pools and the external address of Virtual IPs are considered as local IPs. In other words, they are 'owned' by the firewall, and the firewall will reply to an ARP for one of these addresses.
More details on this change can be seen here: Technical Tip: IP pool and virtual IP behavior changes in FortiOS 6.4, 7.0, 7.2, and 7.4.