Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Duplicating traffic

Hi everyone! I' m new on this forum as well as with managing FortiGate (310b in my case). The problem that i' m experiencing is as following: First few words about my net topology. We have 2 core router/switches in a cluster mode (VRRP). From both, there is a physical connection to the FG ports 1 and 2, which are in redundant mode and defined in a group called LAN. That means, from one core sw to FG port1, from the other (backup) core sw to FG port2. From the FG ports 3 and 4 (also redundant ports - group External) there is a physical connection to 2 layer 2 switches, each port of the FG to one L2 switch. Each L2 sw is connected to a Nokia FW. Hence, there are 2 Nokia' s in a cluster. One thing more, the L2 sw are also connected directly to each other. The problem is as following: When we try to ping from internal LAN (host connected to core sw, for example) to DMZ (which is connected on the FW on a separate physical interface), we get a duplicated reply packet. On the FG there is a firewall policy that allows all traffic from internal addresses to DMZ addresses, and aplying no Protection Profile on this traffic. This is also happening for other traffic, besides icmp. We tested many things, and came to the conclusion that the problem is (probably) related to ARP and STP on the switches. We have tried to forward stp on all 4 ports on the FG but with no luck. Please, any suggestion is more than welcome. This is a rather big issue in our case.
10 REPLIES 10
Not applicable

Hi SvaboVD , You may have to configure forwarding domains. See more details here : " Technical Note : Configuring a FortiGate in Transparent mode with trunks (802.1q - VLANs) and forwarding domains" http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD30083 -J.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors