- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiGate drops traceroute UDP
Hi,
Based on this KB: https://community.fortinet.com/t5/FortiGate/Technical-Note-ICMP-and-UDP-traceroute-functionality-wit....
I know that the UDP based traceroute will be dropped by FortiGate if I try to traceroute to FortiGate' IP address (e.g. management IP).
But for endpoint behind the FortiGate, does FortiGate also drop this UDP based traceroute even I have allowed any in the firewall policy?
Thank you
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Fortigate is expected to take action based on the firewall policy, if you have allowed it ideally it is expected to work fine.
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I see, I think I need to do debug flow to see why the traceroute packet is not sent to endpoint.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, flow debug will give us better idea. Can you make sure the endpoint IP is not configured on Fortigate as any VIP?
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, the endpoint is not configured as any VIP.
The endpoint gateway is on the FortiGate
