Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
aaaa8301
New Contributor

ARP issue in 60F

HI Folks,

I met one very weird issue here with 60F v7.2.4. Two devices are connected to firewall through one managed switch. Firewall and devices are in same sub-work. I could ping other computers from firewall, except for two devices. I mirror the switch port which is connected to firewall, and use wireshark log the traffice. I saw firewall send ARP to the netwrok, and the two devices response the ARP and send the ARP response to firewall. But somehow, firewall doesn't pur these two devices into ARP Table.

If I manually to add these two devices into Firewall ARP Table. I could ping these two devices from firewall console. So I am very confused that why firewall don't like these two devices.

Does anyone have simillar issue before?

 

Best regards.

3 REPLIES 3
hbac
Staff
Staff

Hi @aaaa8301

 

I would suggest taking a packet capture on the FortiGate to see if it receives arp responses or not. You can use this command "diagnose sniffer packet <interface-name> 'arp' 4 0 l" 

 

You can also try to connect those two devices directly to the firewall and see if it works. 

 

Best regards, 

aaaa8301
New Contributor

hi hbac,

I did the "diag sniffer packet, it doesn't show the ARP response. That's why it weird. The port of Firewall is RJ45, the device has LC-100Mb port, I couldn't make them together directly. that's why I put one switch between firewall and these devices.

Regards.

hbac

Hi @aaaa8301

 

It that case, we need to check why arp response doesn't reach the firewall. 

 

Regards,

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors