Hello,
Please help,
I can't ping from User A to user B in the same network/segment.
The topology :
User A -> Access P -> FTG - Access P -> User B
User A : 10.10.4.5
User B : 10.10.4.40
AP : 10.10.3.0/24
I have enable PING in Interface menu.
What might be cause the problem ? Please help
Thanks
Solved! Go to Solution.
Good Night, it-eatwell
Reffering to your post, are the users connected to the Internal Network 10.10.4.0/24 and the APs are on the 10.10.3.0/24?
Try creating the follow Policy
Incoming: 10.10.4.0/24
Outcoming: 10.10.3.0/24
Source: All
Destination: All
Service: Ping.
And create a Reverse Policy too.
Incoming: 10.10.3.0/24
Outcoming: 10.10.4.0/24
Source: All
Destination: All
Service: Ping.
Morning Pedro,
Yes, i have created the firewall policy in forti.
From 10.10.3.0/24 successfully communicate to 10.10.40.0/24, also reverse.
The problem is :
PC A cannot ping to PC B in the same AP (same network).
PC A can ping to PC B in different AP (same network).
Regards,
eatwell
Hi it-eatwell,
I understand that you are unable to access the clients connected to the same subnets but different APs.
Please confirm how the APs are connected to the network. If there is a switch in-between, then we might have to check if the traffic is blocked anywhere in the path.
You might also consider checking if you have enabled 'Block intra-SSID traffic' in tunnel mode which might block communication between the clients connected to the same SSID irrespective of the APs.
https://community.fortinet.com/t5/FortiAP/Techincal-Tip-How-Block-intra-SSID-traffic-option-on-ssid/...
Regards,
Vimala
Created on 04-11-2023 11:30 PM Edited on 04-12-2023 12:50 AM
Hi Vimala,
Thanks for the reply.
The topology :
User A -> Access P -> FTG - Access P -> User B
So APs are directly connected to Forti F300E,10.10.1.1, there are no switches in between.
I'm using Ruijie AP.
Thanks.
Regards,
eatwell
Good Night, it-eatwell
Reffering to your post, are the users connected to the Internal Network 10.10.4.0/24 and the APs are on the 10.10.3.0/24?
Try creating the follow Policy
Incoming: 10.10.4.0/24
Outcoming: 10.10.3.0/24
Source: All
Destination: All
Service: Ping.
And create a Reverse Policy too.
Incoming: 10.10.3.0/24
Outcoming: 10.10.4.0/24
Source: All
Destination: All
Service: Ping.
Morning Pedro,
Yes, i have created the firewall policy in forti.
From 10.10.3.0/24 successfully communicate to 10.10.40.0/24, also reverse.
The problem is :
PC A cannot ping to PC B in the same AP (same network).
PC A can ping to PC B in different AP (same network).
Regards,
eatwell
User | Count |
---|---|
2677 | |
1412 | |
810 | |
703 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.