hi,
I've created secondary IP Address to certain Interface (Internal 2), so we can define on Internal 2 has 2 ip:
ip-1, and ip-2
can I make:
certain host (computer) from ip-1 communicate to specific IP address on ip-2?
If different interface, I can make policy route, how about in this case?
kindly please advice.
thank you
Hi
Just add a firewall rule like this:
somehow still not working.
do you refer to Firewall policy, correct?
correct
My guess is that the FGT silently drops traffic to/from the secondary IP because it doesn't know where to route it.
Primary addresses always get a "connected" static route immediately.
Secondary addresses? Have a look at Dashboard - Network - Routing.
If there is no route for the secondary address / it's subnet, then add one in Network - Static routes.
Of course, with more time and opportunity, you could just debug this with "diag debug flow".
Try this command sequence, redo the ping tests and share the debug logs.
diag debug flow filter addr x.x.x.x
diag debug console timestamp enable
diag debug flow show iprope enable
diag debug flow show function-name enable
diag debug flow trace start 100
diag debug enable
User | Count |
---|---|
2593 | |
1382 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.