Hi there,
When i execute a "diag sniffer packet wan1" I don't see any traffic.
wan1 is in a separate Vdom.
Communication is working and the firewall rule has log option activated.
The FW is an oldie FG200A. What's wrong here?
Best r,
E
The cli command diag debug flow with the filters applied would be your starting point. Maybe the traffic is drop before hitting wan1 ( uRPF, deny-action,etc...)
PCNSE
NSE
StrongSwan
Thanks, Executed without filters I do see some "general traffic" something what I wouldn't expect within this Vdom. But I don't see the traffic I'd like to see.
Than your host is not hitting the firewall. You can bypass the firewall if your traffic is allowed or deny would result in a match in trace.
I would do it again & with filters for either src dst address or port and re-evaluate.
Ken
PCNSE
NSE
StrongSwan
Thanks Ken, I've tried your suggestion. However, even with filters I'm not able to discover the hosts I'm looking for neither the traffic. I've also looked into the Fortianalyzer and shows me the same results. So no traffic and no hosts I'm looking for. A Thing I forgot to mention, I'm looking for VOICE traffic.
"I was able to see the VOICE traffic before"
Best,
E
1>
The diag sniffer packet, shows no traffic
2>
The diag debug flow, shows no traffic
That means that traffic is NOT going thru your fortigate.What does a trace route show between the 2 hosts involved?
Are the two hosts involved on the same local subnet ?
Ken
PCNSE
NSE
StrongSwan
Hi Ken,
1> and 2> yes and yes. Although I agree with your opinion traffic is not hitting the firewall in theory, I'm confused.
Why? People are calling :) The ip softphones are physically connected via a switch to the firewall. Scary isn't it?
Best,
E
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.