Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
madsem
New Contributor

FortiExtender lan extension monodirectional?

Hi all!

Provisioning a FortiExtender following docs and hints in KB, I'm unable to set up a bidirectional communication

Let me explain.

FGT40F has a LAN in 192.168.1.0/24 behind a 1Gb/s internet link.

I want to set up a FEX with a network 192.168.2.0/24 behind a 1Gb/s internet link.

Provisioning work very well, but from 192.168.1.0/24 I can ping anything in 192.168.2.0/24, but from 192.168.2.0/24 I cannot reach anything on 192.168.1.0/24.

Doing some debugging I see on FGT the correct static route to see 192.168.2.0/24, but on FEX I don't see it and I cannot find a working configuration.

I'm doing something wrong or I'm missing something?

Last try was with this doc: https://community.fortinet.com/t5/FortiExtender/Technical-Tip-How-to-setup-FortiExtender-LAN-Extensi... and I can ssh into FEX from FGT without any problem, but any chance to reach 192.168.1.0/24 from 192.168.2.0/24 :(

This configuration is make me going crazy >_>

 

Any hint?

 

Thanks!

 

Sem

Share if you know, learn if you don't :)
Share if you know, learn if you don't :-)
8 REPLIES 8
gfleming
Staff
Staff

What version of FOS are you running?

 

Do you have the policy allowing traffic from LAN Extension network?

 

https://docs.fortinet.com/document/fortigate/7.0.0/new-features/339612/introduce-lan-extension-mode-...

Cheers,
Graham
madsem

I'm on 7.2.3 on FGT and 7.2.2 on FEX.

Yes, I have that policy.

Thanks for your time!

 

Regards,

Sem

Share if you know, learn if you don't :)
Share if you know, learn if you don't :-)
gfleming

Full disclosure, I have never configured this before. But reading through the docs it appears as though the LAN behind the FEX shares the same subnet as the LAN Extension interface on the FGT. So if you have an existing LAN using 192.168.1.0/24 on the FGT, you'll probably need to create a new subnet 192.168.2.0/24 for the LAN Extension interface. Then, you can use this subnet on the FEX LAN as well and point clients to the FGT as the default gateway.

Cheers,
Graham
madsem

This is what I've done... All interfaces configured. I've also make a try with policy that allow those two differents network to talk.

madsem_0-1668934313037.png

Now I'll make some try with a /22, maybe...

Thank you for your hints and time!

 

Regards,

Sem

Share if you know, learn if you don't :)
Share if you know, learn if you don't :-)
gfleming

Do you have two policies? One for FGT LAN interface to FEX Extension interface and one for the reverse from Extension to FGT LAN? That's probably all that is missing. 

 

You do not need routing on the FEX as all routing is taken care of on the FGT. 

 

Changing your subnet form a /24 to a /22 will not change anything here.

Cheers,
Graham
madsem

I've made three policy. 192.169.1.0/24 (lan on local interface) to 192.169.2.0/24 (on FEX interface), 192.169.2.0/24 to 192.169.2.0/24, and the last 192.169.2.0/24 on FEX interface to WAN.

 

About the routing, so I'm expecting to be, but it doesn't.

 

I can confirm that changing subnets it desn't reolve anything, because FGT don't want (and it make sense) overlapped networks on two sides.

 

Today FEX is coming back to our lab, so we can do some testing leaving our customer working with the old configuration. I'll update this thread with some news, I hope.

 

Thanks!

Sem

Share if you know, learn if you don't :)
Share if you know, learn if you don't :-)
gfleming


@madsem wrote:

I've made three policy. 192.169.1.0/24 (lan on local interface) to 192.169.2.0/24 (on FEX interface), 192.169.2.0/24 to 192.169.2.0/24, and the last 192.169.2.0/24 on FEX interface to WAN.

Is that a typo or is that your actual policy that's configured? It should be FEX interface 192.168.2.0/24 to FGT LAN 192.168.1.0/24...

 

Does remote FEX LAN get access to the internet in the configuration? Or is that also not working?

Cheers,
Graham
madsem

It was a typo, sorry! It's as you correct me!

Remote FEX Lan has no access to internet but ping default GW, while FEX can ping and resolve internet public addresses like fortinet.com or google.com.

Today FEX is back to my main office. I'll open a case with FortiTAC and I update here for the solution.

Share if you know, learn if you don't :)
Share if you know, learn if you don't :-)
Labels
Top Kudoed Authors