Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kunglo
New Contributor

FortiGate 200G "traceroute operation not permitted" error — how to fix?

Hi everyone,

Spoiler

สวัสดีทุกคน

ฉันกำลังใช้ **FortiGate 200G** รัน **FortiOS [เวอร์ชัน — ใส่เวอร์ชันของคุณที่นี่ egv7.2.8]**

เมื่อฉันรันคำสั่งต่อไปนี้จาก CLI:

ดำเนินการ traceroute-options source 49.231.244.67
ดำเนินการ traceroute 49.231.244.70
ฉันได้รับข้อความแสดงข้อผิดพลาดนี้:

traceroute ถึง 49.231.244.70 (49.231.244.70), สูงสุด 32 ฮ็อป, 3 แพ็คเก็ตโพรบต่อฮ็อป, แพ็คเก็ต 84 ไบต์
1 49.231.244.70 <m.lannapoly.ac.th> 0.028 มิลลิวินาที
traceroute: sendto: การดำเนินการไม่ได้รับอนุญาต
traceroute: เขียน 49.231.244.70 84 ตัวอักษร, ret=-1

 

มีใครเคยเห็นปัญหานี้มาก่อนหรือไม่?

I updated FGT_200G-v7.2.11.M-build6561-FORTINET and this fixed the issue.

11 REPLIES 11
dingjerry_FTNT

Hi @kunglo ,

 

Could you please provide the following?

 

1) FGT config

2) Routing table on FGT

Regards,

Jerry
kunglo

Actually, the issue I'm seeing is this:
I'm forwarding traffic (FWP) via IP xx.xxx.244.70, and when I perform a traceroute using source IP xx.xxx.244.67, I get an "operation not permitted" message. Interestingly, it appears once, and then subsequent attempts also show "operation not permitted."

Since the FG-200G is still new in our environment, I’m not sure if others have encountered the same issue.

Regarding the FGT config — do you need the full configuration or just specific sections?

Thank you.

 

 

dingjerry_FTNT

It's better with the full FGT config. You may mask the sensitive settings.

 

Also, please show us the network diagram that includes 49.231.244.70.

Regards,

Jerry
dingjerry_FTNT

Hi @kunglo ,

 

Thanks for the routing table info.

 

According to it, it seems that the IP 49.231.244.65 is your default gateway IP, not configured on your FGT.

 

For the ping source option, it's better to use the egress interface IP.

Regards,

Jerry
kunglo

Thanks for your feedback.

Actually, I'm using 49.231.244.67 as the source IP, which is the IP configured on the egress interface (port3) connected to the 49.231.244.64/26 subnet.

So as I understand, this should be correct in this case.

 

However, I'm still seeing the "operation not permitted" when tracerouting to 49.231.244.70. Do you have any further suggestions or ideas why this might happen?

 

Thanks again!

dingjerry_FTNT

Based on your conversation with Yurisk, it seems that you have something like VIP with 49.231.244.70 IP?  

 

If so, we do not encourage testing connectivity in this way from FGT itself.  You need to test it from the Internet or your gateway device.

 

This is why I am asking for your FGT config to confirm whether it is related to a VIP or not.

Regards,

Jerry
kunglo

Thank you for your advice. I personally don’t have any issues, but my customer was curious about this because everything is actually working fine right now, even though this message appears.

Yurisk
SuperUser
SuperUser

I've see recently such issues on FGT-VM (KVM-based) - was a host KVM problem, restarted the FGT-VM and all worked fine. 

In your case - do you get the same error if you traceroute some regular IP, like 8.8.8.8? 

Do you get the error if tracerouting your destination w/o setting the source address?

 

In general, the error means that sending traceroute packets (high port UDP) in general or to the specific destination is prohibited - may be on FGT itself, or a router/firewall this FGT is connected to as its gateway.

 

By the look of it - I'd guess you are trying to traceroute FGT itself, of IP belonging to the routed to the FGT, which will not work.

https://yurisk.info
https://yurisk.info
kunglo
New Contributor

 

When I traceroute to other IPs, it works normally.

 

However, when I try to traceroute to xx.xx.244.70 (which is the IP I have configured for FWP), I receive the following error: mstraceroute: sendto: Operation not permitted

 

As I understand it, when tracerouting to my own forwarded IP like this, I should typically see myself in a single hop, correct?

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors