Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gilfalko
New Contributor III

Cant ping Fortigate unit from outside

Hi, I have 2 internet WAN connections. The second one is for backup. For some reason, I' m unable to ping my backup WAN address. I' m not sure why but I cant get any data to pass from the internet through the unit (200B 5.0). I ticked the PING box on the WAN interface settings. While I can ping the address from my LAN, it' s unavailable from the internet. Packet Capture shows the data as being received but on the other end there' s no response whatsoever when pinging. I have the feeling this is a routing issue as 0.0.0.0 is routed through the main WAN connection. How do I fix this? Thanks!
7 REPLIES 7
gilfalko
New Contributor III

I' ll just emphesize, How can I make sure that whatever data that comes through WAN2 also goes out the same way? Thanks
ede_pfau
SuperUser
SuperUser

I' d say that' s the nature of a backup link - as long as the primary link is up there' s no traffic on the backup. If you sniff the traffic like this
 diag deb ena
 diag sniffer packet any ' icmp and 1.2.3.4'  4
where 1.2.3.4 stands for the WAN2 address, you should see that the ping comes in on WAN2 and the reply leaves on WAN1 via the default route. Remedy: set up ECMP, that is, load balancing on both WAN lines. You can have 2 default routes active at the same time if both have equal distances and priorities. Of course, internet access follows a different pattern then, but you get what you wanted.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
gilfalko
New Contributor III

Thanks for the reply! How do I determine internet access this way? I tested this out I cant access any websites this way...
ede_pfau
SuperUser
SuperUser

FortiOS Handbook, chapter " Advanced Routing" , keyword ECMP. Basically, you create a second default (static) route, routing 0.0.0.0/0 to WAN2, no gateway address. Distance and priority MUST be equal to the existing default route' s values. The net effect is that, if ECMP is working, traffic from even source IP addresses goes out WAN1 and from odd addresses goes out WAN2 (because of the source IP hash method employed by default, round-robin style). In both cases you should get a reply. Of course, you need 2 policies, with NAT enabled.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
gilfalko
New Contributor III

One question though, Is it possible to have separate WANs for individual networks this way? I have a site I' m connected to by IPSEC VPN through our main line. I' d like to also have a second VPN for backup using the backup line. With the method you proposed, wouldnt Round-Robin randomly use my WANs for exit? Thanks again for your help!
ede_pfau
SuperUser
SuperUser

How do I determine internet access this way?
The sniffer command will show you traffic if you ping your FGT' s WAN2 address, both request and reply.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
ede_pfau
SuperUser
SuperUser

No, as the VPN tunnel is tied to a specific port. For backup tunnels there is a phase1 CLI only option which determines the tunnel to watch and to replace in case it fails. Kind of Dead gateway detection for IPsec tunnels.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors