not able to access internal servers IP using Virtual IP. firewall access rules also in place. still facing challenge...
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello
Hello ArviRaja,
Thank you for reaching out. There are a lot of information that needs to be reviewed here for proper recommendations like the cofig of the interfaces, VIP, firewall policy. If you are looking for troubleshoot steps only then best to start with 2 sinffer commands in separate simultaneous cli sessions to monitor the traffic as well as another session with debug flow output:
- sinffer:
# diag sniffer packet any "host x.x.x.x" 4 -------- you can run one sniffer were the address is the external ip and another sniffer for the real ip of the internal server
- debug:
diag de reset
di de flow filter addr x.x.x.x
di de flow filter port <dst port if it is a custom port>
di de flow trace start 10
di de console time en
di de en
Otherwise I would recommend opening a ticket with support if there is a valid support contract.
Thank you,
saleha
FG30E ver 6.2.9
forticare ad fortiguard licenses expired on FG30E
This feature doesn't require a license.
FG30E ver 6.2.9
Hi @ArviRaja,
Is it a new configuration? Please collect debug flow to see why it is not working. You can refer to https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.