Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bartman10
Contributor

From CLI can't ping remote FG LAN IP... Support learns something new!

It seems the order of network ports on a FG is random with no documentation on how this should work or what this could affect...

Let me tell you a story.. about a new 94D that came to play with  my other units.

Say you have a site to site VPN between this unit and another FG.. you can't ping the 94D's lan interface from the remote FG cli. But a client behind the FG can ping the LAN interface of the remote FG. They also said this is how they all work.. Bzzt wrong.. 5 of my other units don'd do this.. I can ping the LAN interface of all of them from the CLI. Support thinks all FG's do this because they use 60D's as test units. 3 support techs refused to believe me as I showed them my 300C, 90D,200D,40C all can ping the lan interface across a VPN tunnel from cli.. After support did more "looking" they now say this is because the VPN tunnels don't have IP addresses by default. When the FG goes to send the ping if the interface does not have an IP address it goes from top to bottom in order. So.. the Site to Site VPN does not have an IP address on the virtual adapter.. that's how the wizard makes it.. that's how it's done in the manual.. but now they just figured out it should or your internal PING from the CLI will go out over the WAN interface... figure that one out..  

It works on some FG models because the LAN port is #1, other models the WAN is #1 and it doesn't work.. They just figured this out.. ? really?

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track.

Over 100 WiFi AP's and growing.

FAZ-200D

FAC-VM 2 node cluster

Friends don't let friends FWF!

300E x3, 200D, 140D, 94D, 90D x2, 80D, 40C, handful of 60E's.. starting to loose track. Over 100 WiFi AP's and growing. FAZ-200D FAC-VM 2 node cluster Friends don't let friends FWF!
0 REPLIES 0
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors