Hi everyone,
สวัสดีทุกคน
ฉันกำลังใช้ **FortiGate 200G** รัน **FortiOS [เวอร์ชัน — ใส่เวอร์ชันของคุณที่นี่ egv7.2.8]**
เมื่อฉันรันคำสั่งต่อไปนี้จาก CLI:
ดำเนินการ traceroute-options source 49.231.244.67 ดำเนินการ traceroute 49.231.244.70 ฉันได้รับข้อความแสดงข้อผิดพลาดนี้:
traceroute ถึง 49.231.244.70 (49.231.244.70), สูงสุด 32 ฮ็อป, 3 แพ็คเก็ตโพรบต่อฮ็อป, แพ็คเก็ต 84 ไบต์1 49.231.244.70 <m.lannapoly.ac.th> 0.028 มิลลิวินาทีtraceroute: sendto: การดำเนินการไม่ได้รับอนุญาตtraceroute: เขียน 49.231.244.70 84 ตัวอักษร, ret=-1
มีใครเคยเห็นปัญหานี้มาก่อนหรือไม่?
I updated FGT_200G-v7.2.11.M-build6561-FORTINET and this fixed the issue.
Hi @kunglo ,
Could you please provide the following?
1) FGT config
2) Routing table on FGT
Created on 06-04-2025 08:10 AM Edited on 06-04-2025 08:19 AM
Actually, the issue I'm seeing is this:
I'm forwarding traffic (FWP) via IP xx.xxx.244.70, and when I perform a traceroute using source IP xx.xxx.244.67, I get an "operation not permitted" message. Interestingly, it appears once, and then subsequent attempts also show "operation not permitted."
Since the FG-200G is still new in our environment, I’m not sure if others have encountered the same issue.
Regarding the FGT config — do you need the full configuration or just specific sections?
Thank you.
It's better with the full FGT config. You may mask the sensitive settings.
Also, please show us the network diagram that includes 49.231.244.70.
Hi @kunglo ,
Thanks for the routing table info.
According to it, it seems that the IP 49.231.244.65 is your default gateway IP, not configured on your FGT.
For the ping source option, it's better to use the egress interface IP.
Thanks for your feedback.
Actually, I'm using 49.231.244.67 as the source IP, which is the IP configured on the egress interface (port3) connected to the 49.231.244.64/26 subnet.
So as I understand, this should be correct in this case.
However, I'm still seeing the "operation not permitted" when tracerouting to 49.231.244.70. Do you have any further suggestions or ideas why this might happen?
Thanks again!
Based on your conversation with Yurisk, it seems that you have something like VIP with 49.231.244.70 IP?
If so, we do not encourage testing connectivity in this way from FGT itself. You need to test it from the Internet or your gateway device.
This is why I am asking for your FGT config to confirm whether it is related to a VIP or not.
Thank you for your advice. I personally don’t have any issues, but my customer was curious about this because everything is actually working fine right now, even though this message appears.
I've see recently such issues on FGT-VM (KVM-based) - was a host KVM problem, restarted the FGT-VM and all worked fine.
In your case - do you get the same error if you traceroute some regular IP, like 8.8.8.8?
Do you get the error if tracerouting your destination w/o setting the source address?
In general, the error means that sending traceroute packets (high port UDP) in general or to the specific destination is prohibited - may be on FGT itself, or a router/firewall this FGT is connected to as its gateway.
By the look of it - I'd guess you are trying to traceroute FGT itself, of IP belonging to the routed to the FGT, which will not work.
When I traceroute to other IPs, it works normally.
However, when I try to traceroute to xx.xx.244.70 (which is the IP I have configured for FWP), I receive the following error: mstraceroute: sendto: Operation not permitted
As I understand it, when tracerouting to my own forwarded IP like this, I should typically see myself in a single hop, correct?
User | Count |
---|---|
2571 | |
1365 | |
796 | |
653 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.