Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ouams_90
New Contributor

Fortigate WAN

Hello everyone; I really need help. I have a FortiGate200F firewall, I have just connected the fiber optic via a Huawei equipment (A810A). my multiservice network: RMS 192.168.141.98/30 my WAN network: 41.111......./30. My ADSL lines work as normally as possible via an SD-WAN and WAN alone. Thank you
17 REPLIES 17
Ouams_90
New Contributor

@hbac 

hi
yes I can ping default gateway of the fiber optic
I was able to access the internet by deactivating all the other pppoe ports and the sd-wan static route 0.0.0.0/0.0.0.0 - 0.0.0.0/0.0.0.0
the problem now is that the connection to the internet only lasts a few minutes and it shuts down internally, but I can ping my wan from the outside, every time I have to disable secondary ip 192.168.141.98/30 in Port 1.
for it to work.

the new static route is: 0.0.0.0/0.0.0.0- 192.168.141.97 for port 1

do you have any idea what the problem is?

Sincerely

hbac

@Ouams_90,

 

I would suggest opening a ticket with Fortinet TAC to troubleshoot this issue. 

 

Regards, 

Ouams_90
New Contributor

hi @hbac 

I can ping my public address from the outside
but locally I don't have internet .

do you have any idea of the problem
a screenshot is attachedCapture d'écran 2023-09-23 113916.png

 

DPadula

Have you added the static route point to your ISP?

Regards
DPadula
Ouams_90

hi @DPadula 

let me explain.
i have configured my wan with two ip addresses provided by my ISP the first one with my public ip address 41.111....../30
the second ip address 192.168.141.98/30 the gateway between my fortigate and the equipment provided by my ISP is 192.168.141.97

static route configuration: destination 0.0.0.0/0.0.0.0 gateway 192.168.141.97 administrative distance 10

from outside I ping my public address
but locally I don't have internet.

DPadula
Staff
Staff

 

 

Regards
DPadula
Kush_Patel
Staff
Staff

Hello @Ouams_90,

 

From the traceroute, i can see the packet was reaching to 172.16.0.1 (x1 interface of FGT, LAN) and then it is being forwarded to default gateway of your FO 192.168.141.97. After that hop, the paket was not being forwarded. You should check with ISP of FO. 

 

Regards.

Ouams_90

hi @Kush_Patel 

but i can ping from outside my public ip address linked to my wan 1 41.111.......

attached screenshot

Capture d'écran 2023-09-23 113916.png

Regards

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors