HI Folks.
Help...
I am creating a new DMZ using a loopback address on fortigate 6.14.3
I have created a couple of VMs that use the IP range of the new DMZ.
From the firewall I can ping the VMs no problem, However from the VMs I cannot ping the loopback interface which would be their default gateway. Not sure what is going on here. Yes PING is enabled on the FG interface.
next
edit "DMZ2"
set vdom "root"
set ip 192.168.4.1 255.255.255.0
set allowaccess ping
set type loopback
set alias "DMZ2"
set role dmz
set snmp-index 62
I have allowed a policy so I should be able to ping from other networks connected to the fortigate physically but no response.
From the fortigate.
FW1 $ exec ping 192.168.4.11
PING 192.168.4.11 (192.168.4.11): 56 data bytes
64 bytes from 192.168.4.11: icmp_seq=0 ttl=255 time=0.0 ms
64 bytes from 192.168.4.11: icmp_seq=1 ttl=255 time=0.0 ms
64 bytes from 192.168.4.11: icmp_seq=2 ttl=255 time=0.0 ms
64 bytes from 192.168.4.11: icmp_seq=3 ttl=255 time=0.0 ms
64 bytes from 192.168.4.11: icmp_seq=4 ttl=255 time=0.0 ms
--- 192.168.4.11 ping statistics ---
5 packets transmitted, 5 packets received, 0% packet loss
round-trip min/avg/max = 0.0/0.0/0.0 ms
VM networks setup fine.
However no arp entry for the 192.168.4.1 address.
any ideas !!
thanks,
Chris.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Perhaps I am missing something because what I'm about to write seems somewhat trivial, but regardless...
If the layer two extends up to the FortiGate, then it can simply be the gateway within that DMZ subnet.
If the traffic is routed, you would have to instruct the gateway of the DMZ subnet to route all the DMZ traffic through the FortiGate, and then route/policy it further on the FortiGate as desired.
I think its a problem within my VMWare.
Yes I wanted to use it as a simple gateway.
thanks for your assistance.
Chris.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.