- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Firewall block icmp ?
hello everyone, im just new here and i have i problem with firewall .i setup like that, when i put firewall alone with internet i can access web gui fortinet ,but when i put i after router and config like that ,i can ping each other ,router can ping 8.8.8.8 but firewall not .I dont know what problem with my firewall now,pls help.sorry for m
- Labels:
-
FortiBridge
-
FortiClient
-
FortiGate
-
FortiWeb
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello
Do you want to access firewall GUI from Internet or you just want your firewall to ping Internet?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thanks for your respond,i want both.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Starting from your description I guess you have to configure default route on the firewall (next hop 192.168.1.10) and enable NAT on router R1 (or fix the routing from Net). If you want to reach FGT from the internet you have to configure DNAT/port forwarding in the router.
If you have found a solution, please like and accept it to make it easily accessible for others.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Hisoka74,
When connected to the R1, on FortiGate, can you do the following command "execute traceroute 8.8.8.8" and see is the next hop is R1? If yes then the traffic must be drop on R1 and you may need to run debug to see why they are dropping.
Regards,
Minh
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello
As I can see you are able to access internet directly but not after connecting router.
For this you need to enable internet on router and need to give static route(Gateway will be router interface ip )address.
Regards
Mayank Sharma
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
thanks for your respond,you mean enable ip nat outside 192.168.10.1 and give static route right
