hi There,
this might be ridiculous question, but I want to make sure I didn't miss something while setup.
we use Fortigate 30E, and
we have ISP that provide IP Public static. information they given:
IP 1.1.1.1 / 29
subnet 255.255.255.248 / 29
gateway 1.1.1.2
dns 8.8.8.8 ; 8.0.8.0
then we made config on fortigate:
- interface WAN
IP : 1.1.1.1
subnet : 255.255.255.248
ping, https, fmg-access: checked
- static route
destination: 0.0.0.0
gateway: 1.1.1.2
other setting: <default>
- DNS
8.8.8.8, 8.0.8.0
now connect all cable.
LED WAN, all on.
but when I ping to IP 1.1.1.1 from outside network, it said:
ttl expire in transit
but I can ping to 1.1.1.2 and give reply.
am I missed something?
need help. thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Nothing ridiculous but a basic routing troubleshooting.
Just traceroute from ouside toward 1.1.1.1 to see if you can get to at least the GW. My guess it your ISP's routing problem.
Always check the routing table in GUI or CLI (get router info routing-table all) to make sure the static default route is pointing to the GW.
By the way, if it's older than 6.0, check if trusthosts are configured, then ping wouldn't get reply if the source is not in the list of trusthosts. I think they changed this behavior after 6.0.
helllo.
thanks for response.
try tracert from outside network, time out until no end.
I see installed device, the connection strange to me.
FO (from tower base) -> Mikrotik -> RJ45
ths rj45 go to Fortigate
If your admin account is not locked down to trusted hosts then the mikrotik must be blocking incoming traffic perhaps?
toshiesumi wrote:hello,Nothing ridiculous but a basic routing troubleshooting.
Just traceroute from ouside toward 1.1.1.1 to see if you can get to at least the GW. My guess it your ISP's routing problem.
Always check the routing table in GUI or CLI (get router info routing-table all) to make sure the static default route is pointing to the GW.
By the way, if it's older than 6.0, check if trusthosts are configured, then ping wouldn't get reply if the source is not in the list of trusthosts. I think they changed this behavior after 6.0.
sorry missed to answer.
yes, static default route pointing to gateway 1.1.1.2 for interface WAN
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.