Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
arie_arie
New Contributor III

FortiGate drops traceroute UDP

Hi,

 

Based on this KB: https://community.fortinet.com/t5/FortiGate/Technical-Note-ICMP-and-UDP-traceroute-functionality-wit....

I know that the UDP based traceroute will be dropped by FortiGate if I try to traceroute to FortiGate' IP address (e.g. management IP).

But for endpoint behind the FortiGate, does FortiGate also drop this UDP based traceroute even I have allowed any in the firewall policy?

 

Thank you

4 REPLIES 4
srajeswaran
Staff
Staff

Fortigate is expected to take action based on the firewall policy, if you have allowed it ideally it is expected to work fine.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
arie_arie

Hi,

I see, I think I need to do debug flow to see why the traceroute packet is not sent to endpoint.

srajeswaran

Yes, flow debug will give us better idea. Can you make sure the endpoint IP is not configured on Fortigate as any VIP?

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
arie_arie

Yes, the endpoint is not configured as any VIP.

The endpoint gateway is on the FortiGate

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors