It seems the order of network ports on a FG is random with no documentation on how this should work or what this could affect...
Let me tell you a story.. about a new 94D that came to play with my other units.
Say you have a site to site VPN between this unit and another FG.. you can't ping the 94D's lan interface from the remote FG cli. But a client behind the FG can ping the LAN interface of the remote FG. They also said this is how they all work.. Bzzt wrong.. 5 of my other units don'd do this.. I can ping the LAN interface of all of them from the CLI. Support thinks all FG's do this because they use 60D's as test units. 3 support techs refused to believe me as I showed them my 300C, 90D,200D,40C all can ping the lan interface across a VPN tunnel from cli.. After support did more "looking" they now say this is because the VPN tunnels don't have IP addresses by default. When the FG goes to send the ping if the interface does not have an IP address it goes from top to bottom in order. So.. the Site to Site VPN does not have an IP address on the virtual adapter.. that's how the wizard makes it.. that's how it's done in the manual.. but now they just figured out it should or your internal PING from the CLI will go out over the WAN interface... figure that one out..
It works on some FG models because the LAN port is #1, other models the WAN is #1 and it doesn't work.. They just figured this out.. ? really?
300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track.
Over 100 WiFi AP's and growing.
FAZ-200D
FAC-VM 2 node cluster
Friends don't let friends FWF!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1709 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.