Hello,
I want to test a FortiGate with its security functions in my existing home environment without changing the existing internet connection or any other network configuration on the router with its WAN access.
For this I place the FGT inside the local (same) subnet. I put static routes on my client so that google.com and www.google.com are going through the FGT. On the FGT there is only one static route that points to the router that has WAN connection.
Actual setting is as following:
Client (192.168.0.15) >> FortiGate (192.168.0.245) >> Router (192.168.0.250) >> WAN
After set up the static routes on the client for Google the ping and traceroute on the clients points to the FortiGate.
Also on the FortiGate there is this ICMP traffic visible in the diagnostics packet view. However, all of the test policies I created on the FortiGate do not have any hit, also the forwarding log is empty, no traffic, and so i cannot play with the security profiels and log settings on the firewall.
Please help me. Where is the fault in this scenario or at which step am I wrong in thinking herewith?
Daniel
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @daniel337 ,
- Can you please share the policy and following debugs while pinging to google from client machine:
di de reset
diagnose debug flow filter addr <src-addr> <dst-addr> and
di de flow filter proto 1
diagnose debug flow show function enable
diagnose debug console timestamp enable
diagnose debug flow show iprope enable
diagnose debug flow trace start 30
diagnose debug enable
Since all the nodes are in the same subnet the reply from the router will not go through the FGT, it will reach the Client directly.
If you want to do this with less changes, I would suggest to create another subnet for the clients (ex. 192.168.5.0/24) in FGT and enable NAT in the firewall policy that allows the client traffic and to use 192.168.0.245 as an Outgoing Interface. By doing this you don't need any change in the router as all the traffic will appear as sourced by 192.168.0.245.
Hello , as per your topology :
Client (192.168.0.15) >> FortiGate (192.168.0.245) >> Router (192.168.0.250) >> WAN
You can consider configuring wan connection on the fgt to have better control on traffic, but it will filter all your traffic.
you can also consider connecting 1 port from ISP modem to FGT configure it as wan then connect your pc with the FGT and use UTM as per your testing requirements
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.