Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ITB
New Contributor

Fortigate 100 , connection lan to one vlan problem!

Hello , we have LAN address 10.0.0.0\23 and two vlan's in zone VLAN_10 10.10.10.0\24 and VLAN_15 15.15.15.0\24, firewall polices was created Lan to Zone(with two vlan) . Lan 10.0.0.0 can ping vlan15( 15.15.15.0) but can't ping vlan10 (10.10.10.0)? Any idea?  Vlan's ping each other 15.15.15.x to 10.10.10.x and 10.10.10.x to 15.15.15.x.

1 Solution
knagaraju
Staff
Staff

Hi ITB,


As I understand, ping is not working in from LAN address 10.0.0.0\23 to VLAN_10 10.10.10.0\24.
Reverse route and firewall policy are the two things which are to be checked. Hence, I suggest you to capture the below debug logs from fortigate cli
diagnose debug reset
diagnose debug flow filter addr 10.10.10.X >>>where X is the exact IP address of the source.
diagnose debug flow filter proto 1
diagnose debug flow trace start 1000
diagnose debug enable

Please initiate ping after running the above commands in fortigate cli

to disable the debugs please run 
di de reset
di de di

Regards
Nagaraju.


View solution in original post

3 REPLIES 3
Anthony_E
Community Manager
Community Manager

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
knagaraju
Staff
Staff

Hi ITB,


As I understand, ping is not working in from LAN address 10.0.0.0\23 to VLAN_10 10.10.10.0\24.
Reverse route and firewall policy are the two things which are to be checked. Hence, I suggest you to capture the below debug logs from fortigate cli
diagnose debug reset
diagnose debug flow filter addr 10.10.10.X >>>where X is the exact IP address of the source.
diagnose debug flow filter proto 1
diagnose debug flow trace start 1000
diagnose debug enable

Please initiate ping after running the above commands in fortigate cli

to disable the debugs please run 
di de reset
di de di

Regards
Nagaraju.


ITB
New Contributor

Hi knagaraju, 

Thank you for your answer, i found problem and fix it. 

 

Regards

Labels
Top Kudoed Authors