Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

FG-100A problems with updates, ping & browsing

We have recently purchased a FG-100A with 1 yr services bundle. I have upgraded the firmware to version 3.00,build0247,060417. I have been observing very weird behavior on the FG-100A. 1) After each restart of the firewall the updates are gone & Web Filtering, antispam shows Not Licensed. also all AV, IPS update lights are flashing red. 2) on the fortiguard center page the test availability button always shows DNS error. No matter if the DNS server is readily available on ping. 3) If we ping the firewall wan1 address from outside, we get a request timeout even though the gateway never times out. 4) More strange is if we keep a continuous ping on wan1 whenever we hit the status link on the web manager gui we get pings briefly, then it again goes back to timeout. 5) Even after putting the override ip address the updates do not take place. 6) The surfing through the firewall is at a standstill. 7) On the web manager gui only the status link comes up very fast. all other pages time out. Please help urgently as the entire campus internet access is down & this is the admission season.
28 REPLIES 28
UkWizard
New Contributor

Could be a speed negotiation issue with the FGT->Router Link ? Could try hard setting one speed (via the command line). replace the cable between the router and the fortinet as well. This is very bizarre behaviour. When you plug the pc in place of the firewall, do you use the firewalls IP address ? or another from your range ? Also check your external interfaces subnet mask is correct, as per the ISP supplied details. A mismatch can cause all sorts of strange behaviour. Last resort if all this fails to help, you could switch to another physical port on the firewall. In other words start using WAN2 port instead of WAN1. This will need resetting up of all the rules though. To eliminate a physical port problem, that could be damaged from a possible power spike due to the power losses. Is the router also on the UPS as well ? if still stuck, are you sure it isnt the Router thats behaving strangely ? have you also connected a pc via crossover to the external port, using another external ip address and see if the ping to the firewall works ?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

No it cant be the router becouse we have used the exact same settings as on the firewall wan1 port on the test PC & it works every time. So no doubt about it. It can not be a wan1 port problem because we have 2 ISP links ( two separate isp links from two separate companies) & we observe exactly same behaviour on the second ISP link too which is connected to the wan2 port of the FG-100A. And we have tested that link too on a separate PC with exactly same settings as on wan2 port. It can not be cables or anything like that cause we use the same set when we test on the PC' s. Thanks for your replies & patience. Much appreciated. I am baffeled here. I have setup many many firewalls but this is the first from fortinet. Fortinet suport just advised me to change the DNS address but we had already tried that & we have also verified that the DNS server addresses we put in FG-100A are working ok.
UkWizard
New Contributor

aha, i didnt know you had two isp links, that opens a whole new list of possibles. Whats your static routing configuration ? Do you have any policy routing setup ?
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Here we go again. Power is back; we have restarted the firewall & exactly the same problems. Static : IP Mask Gateway Device Distance 0.0.0.0 0.0.0.0 isp2 gateway address wan2 10 0.0.0.0 0.0.0.0 isp1 gateway address wan1 10 Policy : # Incoming Outgoing Source Destination 14 internal dmz1 0.0.0.0 / 0.0.0.0 172.21.0.0 / 255.255.0.0 [Delete] [Edit] [Move To] 1 internal wan1 10.1.1.0 / 255.255.255.0 0.0.0.0 / 0.0.0.0 [Delete] [Edit] [Move To] 2 internal wan1 10.1.2.0 / 255.255.255.0 0.0.0.0 / 0.0.0.0 [Delete] [Edit] [Move To] 6 internal wan1 10.1.6.0 / 255.255.255.0 0.0.0.0 / 0.0.0.0 [Delete] [Edit] [Move To] 7 internal wan1 10.1.11.0 / 255.255.255.0 0.0.0.0 / 0.0.0.0 [Delete] [Edit] [Move To] 8 internal wan1 10.1.12.0 / 255.255.255.0 0.0.0.0 / 0.0.0.0 [Delete] [Edit] [Move To] 9 internal wan1 10.1.13.0 / 255.255.255.0 0.0.0.0 / 0.0.0.0 [Delete] [Edit] [Move To] 10 internal wan1 10.1.14.0 / 255.255.255.0 0.0.0.0 / 0.0.0.0 [Delete] [Edit] [Move To] 11 internal wan1 10.1.15.0 / 255.255.255.0 0.0.0.0 / 0.0.0.0 [Delete] [Edit] [Move To] 12 internal wan1 10.1.16.0 / 255.255.255.0 0.0.0.0 / 0.0.0.0 [Delete] [Edit] [Move To] 13 internal wan1 10.1.17.0 / 255.255.255.0 0.0.0.0 / 0.0.0.0 [Delete] [Edit] [Move To] 3 internal wan2 10.1.0.0 / 255.255.0.0 0.0.0.0 / 0.0.0.0 I hope that can help you help me !!
UkWizard
New Contributor

Move the Wan2 static route entry down in the list. if that doesnt fix it, take out the wan2 entry and the policy route entry wan2 to see what happens, most definately a routing issue then. Also ensure you have the ping server options configured in the wan1 and wan2 interface settings, so they can detect a link down. probably the power failures are causing ping pongs between the links.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Wow !! You are a GURU. Thanks a TON. I just changed the distance of wan2 static route from 10 to 12 to indicate its the second choice & it is working like a rocket now. All updates done in under 2 minutes. One question. Will this affect my policy based routes? As you can see from the policy routes I posted I want only certain subnets to go through wan1 & all others through wan2.
Not applicable

Well I am sorry to report that although wan1 is now working fine( with the changed statis route distance), browsing through wan2 has stopped. Any ideas?
UkWizard
New Contributor

you do not change the distance, just the order of the routes (ie have wan1 at the top, not wan2). Changing the distance would effectively make the wan2 a backup link only.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Any particular reason why wan2 should be in second position? Right now I am changing the static routes positions. But if you can explain the question above it would be help me clear up my understanding.
UkWizard
New Contributor

this makes wan1 the primary link, and will be used for the updates and should then respond to pings. And hopefully resolve the issue. Normally, you would create wan1 and wan2 with same distances, then only have policy routes for traffic that you want ' forced' down wan2. So you would then not need the wan1 entries in the policy routing. There has to be a default wan connection, its a bit unclear i know. its also unpredictable sometimes, so if you can do without using wan2 altogether, except in case of a backup, thats even better.....
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors