Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
h_celik
New Contributor II

FortiDeceptor, Monitor IP and Decoy IPs not reachable

Hello,

 

I deployed fortideceptor version 5.3.0. But I don't have access from anotether networks to fortideceptor even though create firewall rule. This issue isnt related vm nic card, vm use vmxnet. Also I configured vmware port group proparties like promiscuous mode, mac address changes and forged transmits. If I try to send ping from fortideceptor mgmt ip to a deployment network monitor ip  it fails. But if I open nat in policy, it will be success. Where could I have gone wrong?

 

nic.jpeg

v-switch.jpeg

vlan.jpeg

Regards

Regards
2 REPLIES 2
AEK
SuperUser
SuperUser

Hi Celik

Since it works with NAT then this is clearly a routing problem, and is not specific to FortiDeceptor.

As you have set the default route through the MGMT interface, that means when you ping the VM on its second port, the VM will try to reply from the MGMT interface, which is blocked by the firewall.

If you set the default gateway through the second interface you will fix the issue, but in that case you will have the same issue on MGMT.

AEK
AEK
h_celik
New Contributor II

I added a new network card to deceptor. This card is tagged to vlan 18 in vmware for example. I selected this port in the deployment network settings. I don't know if it's because I tried a lot, but fortigate had a lot of macs for some ip. I removed the ones I didn't understand, but I couldn't see in the device inventory that any mac address was created in the firewall for the monitor interface.. I pinged the monitor interface from Deceptor and started packet sniffing in the firewall. I saw an arp query coming, but there is no mac address to tell in the firewall

Last time I tried it, I got ping when I turned on nat, but now there is no ping.

 

Monitor interface ip: 10.10.0.5

Deceptor port3 ip: 10.10.0.4


fgt-sniff.png

Regards

Regards
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors