I'm currently setting up a FortiGate firewall and facing a strange issue. The FortiGate WAN interface is directly connected to my ISP router.
From the FortiGate, I can ping the ISP gateway successfully.
However, from the ISP router side (or any host behind it), I cannot ping the FortiGate IP.
Here’s what I’ve checked so far:
Ping is enabled on the WAN interface (set allowaccess ping is configured).
The interface is up, IP is correctly assigned, and the cable is physically connected.
No local-in policy is blocking ICMP.
No trusted hosts are configured under the admin settings.
Subnet and default routes appear correct.
and when I connect that ips wire to my laptop it can get the internet access and able to ping my ip from outside network.
Solved! Go to Solution.
AHM_MANINAGAR_MNG # get router info routing-table details 103.240.162.91
Routing table for VRF=0
Routing entry for 0.0.0.0/0
Known via "static", distance 1, metric 0, best
vrf 0 185.75.142.113, via lan2 inactive
* vrf 0 43.250.164.190, via wan
If you see above output your active default route is only available via wan but you are pinging lan2 IP address and hence reverse path is failing
You are not able to ping lan2 IP because default route shows inactive via lan2. It could be because of sdwan perf sla down for lan2
hey guys issue has been solved the gateway ip was inserted wrong. thanks for all of your support.
User | Count |
---|---|
2637 | |
1400 | |
810 | |
678 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.