Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
h_celik
New Contributor II

FortiDeceptor, Monitor IP and Decoy IPs not reachable

Hello,

 

I deployed fortideceptor version 5.3.0. But I don't have access from anotether networks to fortideceptor even though create firewall rule. This issue isnt related vm nic card, vm use vmxnet. Also I configured vmware port group proparties like promiscuous mode, mac address changes and forged transmits. If I try to send ping from fortideceptor mgmt ip to a deployment network monitor ip  it fails. But if I open nat in policy, it will be success. Where could I have gone wrong?

 

nic.jpeg

v-switch.jpeg

vlan.jpeg

Regards

Regards
1 REPLY 1
AEK
SuperUser
SuperUser

Hi Celik

Since it works with NAT then this is clearly a routing problem, and is not specific to FortiDeceptor.

As you have set the default route through the MGMT interface, that means when you ping the VM on its second port, the VM will try to reply from the MGMT interface, which is blocked by the firewall.

If you set the default gateway through the second interface you will fix the issue, but in that case you will have the same issue on MGMT.

AEK
AEK
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors