HI Folks,
I met one very weird issue here with 60F v7.2.4. Two devices are connected to firewall through one managed switch. Firewall and devices are in same sub-work. I could ping other computers from firewall, except for two devices. I mirror the switch port which is connected to firewall, and use wireshark log the traffice. I saw firewall send ARP to the netwrok, and the two devices response the ARP and send the ARP response to firewall. But somehow, firewall doesn't pur these two devices into ARP Table.
If I manually to add these two devices into Firewall ARP Table. I could ping these two devices from firewall console. So I am very confused that why firewall don't like these two devices.
Does anyone have simillar issue before?
Best regards.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @aaaa8301,
I would suggest taking a packet capture on the FortiGate to see if it receives arp responses or not. You can use this command "diagnose sniffer packet <interface-name> 'arp' 4 0 l"
You can also try to connect those two devices directly to the firewall and see if it works.
Best regards,
hi hbac,
I did the "diag sniffer packet, it doesn't show the ARP response. That's why it weird. The port of Firewall is RJ45, the device has LC-100Mb port, I couldn't make them together directly. that's why I put one switch between firewall and these devices.
Regards.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.