Hi all,
I've got a strange behaviour but I cannot figure out why.
I have a couple of ADSL modems (in bridge mode) connected to wan1 and wan2 of my fortigate 60D.
I created a load-balanced wan on the firewall which.
The modems have an IP on 192.168.200.0/29 where the management GUI responds.
To be able to reach these addresses I created a policy which NAT the packet directed to this address behind an address belonging to the same network.
Then I created a static route to direct the packet to the right interface, wan1 or wan2, depending on the destination target.
Despite this I can reach one modem GUI only while the other is not responding.
Of course If I directli connect the modem to my PC I am able to browse its GUI.
Do you have any idea about what I am missing?
Here you are the flow trace of the packet directed to the modems:
MODEM1 (working)
id=20085 trace_id=7 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=1, 10.9.10.100:21859->192.168.200.1:8) from internal. code=8, type=0, id=21859, seq=0." id=20085 trace_id=7 func=init_ip_session_common line=4620 msg="allocate a new session-000781c6" id=20085 trace_id=7 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw-192.168.200.1 via wan1" id=20085 trace_id=7 func=fw_forward_handler line=675 msg="Allowed by Policy-9: SNAT" id=20085 trace_id=7 func=__ip_session_run_tuple line=2596 msg="SNAT 10.9.10.100->192.168.200.3:62464" id=20085 trace_id=8 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=1, 192.168.200.1:62464->192.168.200.3:0) from wan1. code=0, type=0, id=62464, seq=0." id=20085 trace_id=8 func=resolve_ip_tuple_fast line=4530 msg="Find an existing session, id-000781c6, reply direction" id=20085 trace_id=8 func=__ip_session_run_tuple line=2610 msg="DNAT 192.168.200.3:0->10.9.10.100:21859" id=20085 trace_id=8 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw-10.9.10.100 via internal" id=20085 trace_id=9 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=1, 10.9.10.100:21859->192.168.200.1:8) from internal. code=8, type=0, id=21859, seq=1." id=20085 trace_id=9 func=resolve_ip_tuple_fast line=4530 msg="Find an existing session, id-000781c6, original direction" id=20085 trace_id=9 func=__ip_session_run_tuple line=2596 msg="SNAT 10.9.10.100->192.168.200.3:62464" id=20085 trace_id=10 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=1, 192.168.200.1:62464->192.168.200.3:0) from wan1. code=0, type=0, id=62464, seq=1." id=20085 trace_id=10 func=resolve_ip_tuple_fast line=4530 msg="Find an existing session, id-000781c6, reply direction" id=20085 trace_id=10 func=__ip_session_run_tuple line=2610 msg="DNAT 192.168.200.3:0->10.9.10.100:21859"
MODEM2 (NOT working)
id=20085 trace_id=11 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=2, 192.168.200.2:0->224.0.0.1:0) from wan2. " id=20085 trace_id=11 func=resolve_ip_tuple_fast line=4530 msg="Find an existing session, id-0005ef78, original direction" id=20085 trace_id=12 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=2, 192.168.200.2:0->224.0.0.1:0) from wan2. " id=20085 trace_id=12 func=resolve_ip_tuple_fast line=4530 msg="Find an existing session, id-0005ef78, original direction" id=20085 trace_id=13 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=1, 10.9.10.100:33379->192.168.200.2:8) from internal. code=8, type=0, id=33379, seq=0." id=20085 trace_id=13 func=init_ip_session_common line=4620 msg="allocate a new session-00078386" id=20085 trace_id=13 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw-192.168.200.2 via wan2" id=20085 trace_id=13 func=fw_forward_handler line=675 msg="Allowed by Policy-9: SNAT" id=20085 trace_id=13 func=__ip_session_run_tuple line=2596 msg="SNAT 10.9.10.100->192.168.200.3:62464" id=20085 trace_id=14 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=1, 10.9.10.100:33379->192.168.200.2:8) from internal. code=8, type=0, id=33379, seq=1." id=20085 trace_id=14 func=resolve_ip_tuple_fast line=4530 msg="Find an existing session, id-00078386, original direction" id=20085 trace_id=14 func=__ip_session_run_tuple line=2596 msg="SNAT 10.9.10.100->192.168.200.3:62464" id=20085 trace_id=15 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=1, 10.9.10.100:33379->192.168.200.2:8) from internal. code=8, type=0, id=33379, seq=2." id=20085 trace_id=15 func=resolve_ip_tuple_fast line=4530 msg="Find an existing session, id-00078386, original direction" id=20085 trace_id=15 func=__ip_session_run_tuple line=2596 msg="SNAT 10.9.10.100->192.168.200.3:62464" id=20085 trace_id=16 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=1, 10.9.10.100:33379->192.168.200.2:8) from internal. code=8, type=0, id=33379, seq=3." id=20085 trace_id=16 func=resolve_ip_tuple_fast line=4530 msg="Find an existing session, id-00078386, original direction" id=20085 trace_id=16 func=__ip_session_run_tuple line=2596 msg="SNAT 10.9.10.100->192.168.200.3:62464" id=20085 trace_id=17 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=2, 192.168.200.2:0->224.0.0.1:0) from wan2. " id=20085 trace_id=17 func=resolve_ip_tuple_fast line=4530 msg="Find an existing session, id-0005ef78, original direction"
Thank You
Regards
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
These devices are on two different interfaces. Make 2 unique transfer subnets and try again. (192.168.200.0/30 and 192.168.200.4/30 for example)
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
These devices are on two different interfaces. Make 2 unique transfer subnets and try again. (192.168.200.0/30 and 192.168.200.4/30 for example)
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
I separated the two subnet:
modem1: 192.168.200.1/30 NAT:192.168.200.2
modem: 192.168.200.5/30 NAT:192.168.200.6
but it looks there is the same behaviour. I cannot see the packets replied by the modem2:
MODEM1
2016-01-28 08:09:40 id=20085 trace_id=1222 func=init_ip_session_common line=4620 msg="allocate a new session-00097fc1" 2016-01-28 08:09:40 id=20085 trace_id=1222 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw-192.168.200.1 via wan1" 2016-01-28 08:09:40 id=20085 trace_id=1222 func=fw_forward_handler line=675 msg="Allowed by Policy-9: SNAT" 2016-01-28 08:09:40 id=20085 trace_id=1222 func=__ip_session_run_tuple line=2596 msg="SNAT 10.9.10.100->192.168.200.2:65198" 2016-01-28 08:09:40 id=20085 trace_id=1223 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=6, 192.168.200.1:80->192.168.200.2:65198) from wan1. flag [S.], seq 4225730003, ack 2280903650, win 2100" 2016-01-28 08:09:40 id=20085 trace_id=1223 func=resolve_ip_tuple_fast line=4530 msg="Find an existing session, id-00097fc1, reply direction" 2016-01-28 08:09:40 id=20085 trace_id=1223 func=__ip_session_run_tuple line=2610 msg="DNAT 192.168.200.2:65198->10.9.10.100:65198" 2016-01-28 08:09:40 id=20085 trace_id=1223 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw-10.9.10.100 via internal" 2016-01-28 08:09:40 id=20085 trace_id=1224 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=6, 10.9.10.100:65198->192.168.200.1:80) from internal. flag [.], seq 2280903650, ack 4225730004, win 65535"
MODEM2
2016-01-28 08:13:04 id=20085 trace_id=1322 func=init_ip_session_common line=4620 msg="allocate a new session-00098095"
2016-01-28 08:13:04 id=20085 trace_id=1322 func=vf_ip4_route_input line=1596 msg="find a route: flags=00000000 gw-192.168.200.5 via wan2"
2016-01-28 08:13:04 id=20085 trace_id=1322 func=fw_forward_handler line=675 msg="Allowed by Policy-10: SNAT"
2016-01-28 08:13:04 id=20085 trace_id=1322 func=__ip_session_run_tuple line=2596 msg="SNAT 10.9.10.100->192.168.200.6:65212"
2016-01-28 08:13:05 id=20085 trace_id=1323 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=6, 10.9.10.100:65211->192.168.200.5:80) from internal. flag , seq 585892197, ack 0, win 65535"
2016-01-28 08:13:05 id=20085 trace_id=1323 func=resolve_ip_tuple_fast line=4530 msg="Find an existing session, id-00098094, original direction"
2016-01-28 08:13:05 id=20085 trace_id=1323 func=__ip_session_run_tuple line=2596 msg="SNAT 10.9.10.100->192.168.200.6:65211"
2016-01-28 08:13:05 id=20085 trace_id=1324 func=print_pkt_detail line=4469 msg="vd-root received a packet(proto=6, 10.9.10.100:65212->192.168.200.5:80) from internal. flag , seq 3535325209, ack 0, win 65535"
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.