Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Vatsal_shah
New Contributor II

Inferface is up still cant ping from outside

I'm currently setting up a FortiGate firewall and facing a strange issue. The FortiGate WAN interface is directly connected to my ISP router. 

From the FortiGate, I can ping the ISP gateway successfully.
However, from the ISP router side (or any host behind it), I cannot ping the FortiGate IP.

Here’s what I’ve checked so far:

  • Ping is enabled on the WAN interface (set allowaccess ping is configured).

  • The interface is up, IP is correctly assigned, and the cable is physically connected.

  • No local-in policy is blocking ICMP.

  • No trusted hosts are configured under the admin settings.

  • Subnet and default routes appear correct.

and when I connect that ips wire to my laptop it can get the internet access and able to ping my ip from outside network.Screenshot 2025-06-15 033932.png

1 Solution
sjoshi

AHM_MANINAGAR_MNG # get router info routing-table details 103.240.162.91

Routing table for VRF=0
Routing entry for 0.0.0.0/0
Known via "static", distance 1, metric 0, best
vrf 0 185.75.142.113, via lan2 inactive
* vrf 0 43.250.164.190, via wan

If you see above output your active default route is only available via wan but you are pinging lan2 IP address and hence reverse path is failing
You are not able to ping lan2 IP because default route shows inactive via lan2. It could be because of sdwan perf sla down for lan2

If you have found a solution, please like and accept it to make it easily accessible to others.
Fortinet Certified Expert (FCX) | #NSE8-003459
Salon Raj Joshi

View solution in original post

20 REPLIES 20
Vatsal_shah
New Contributor II

hey guys issue has been solved the gateway ip was inserted wrong. thanks for all of your support.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors