Hi,
I deployed forti in aws.
the forti deployed in az 1a.
I have 2 subnets, 1a and 1b.
I attached to forti 2 eni
1 eni for the wan traffic.
1 eni in 1a az.
in the subnets route table, I route 0.0.0.0/0 traffic to eni that is attached to forti.
I attached the relevant security groups for the eni and for the ec2 machines.
I facing with problem that subnet 1b don't have outbout connection and I cant connect directly to the ec2 machines in subnet 1b, I can connect only from the 1a ec2 machines.
What I configured not correctly?
Thanks
Daniel
Solved! Go to Solution.
Hi @issa00 ,
I solved the issue.
For subnets on another AZ that route to Internal ENI, you need to set the gateway IP for the first IP in the ENI subnet. The first IP of the subnet is to the internal AWS route.
For example Test-1b subnet is on 1b AZ so the "Gateway IP" will be the first IP in subnet 1a attached to subnet because the eni is on 1a AZ.
Hi Daniel,
Check the below from your end. Hopefully one of them should solve the issue.
Let me know if above configurations are correct and still cannot directly conect to EC2s in 1b.
Hi @issa00 ,
The first three sections are correctly defined.
I didn`t understand the 4 section, how can I verify it can handle traffic from 1b?
if you mean if I disable the source/dest check, I disable it.
Thanks
Hi @issa00 ,
I solved the issue.
For subnets on another AZ that route to Internal ENI, you need to set the gateway IP for the first IP in the ENI subnet. The first IP of the subnet is to the internal AWS route.
For example Test-1b subnet is on 1b AZ so the "Gateway IP" will be the first IP in subnet 1a attached to subnet because the eni is on 1a AZ.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.