Description | In some cases, it is possible to reach the FortiGate via ping, but it is not possible to take SSH or Web access(GUI) access to the firewall. This article will describe how to troubleshoot this issue. |
Scope | FortiGate. |
Solution |
The user is not able to take web and SSH access of the firewall. The user is unable to load web GUI access of FortiGate: Check the public as well as private IP address of the system and run the debug flow on the FortiGate.
The debug output shows when the user client (10.9.16.3) tries to access Web GUI access. msg=”iprope_in_check() check failed on policy 0, drop” is visible and the request for web access is denied. This is because host 10.9.16.3 is not added as a trusted host on FortiGate. To fix this issue, 10.9.16.3/32 will be configured as a trusted host
To configure a trusted host for the admin account:
Adding a trusted host using CLI:
After adding a trusted host, again it is possible to try to take Web GUI access of FortiGate. This time, it is possible to access the web GUI of FortiGate successfully.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.