- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Internet connectivity issue at the pc connected to my LAN interface despite policy rules configured
I can't access internet from my pc that is in the same subnet as the LAN port,
Firewall policies are created (LAN-WAN) dst lan port address / src all, and (WAN-LAN).
- Labels:
-
DNS
-
FortiClient
-
FortiGate
-
Interface
-
SD-WAN
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello BKR
You can start by enabling all traffic logging on the related policy, then check in traffic log if your traffic is being allowed or blocked.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
Please provide the below information;
CLI 1:
# diagnose debug flow filter addr x.x.x.x<------- Destination address
# diagnose debug flow show function-name enable
# diagnose debug flow show iprope enable
# diagnose debug flow trace start 100
# diagnose debug enable
Initiate ping from the PC to Internet (Eg: 8.8.8.8)
# diagnose debug disable <------------ Run this command to disable debug
CLI 2:
# diagnose sniffer packet any "host < destination IP >" 4 0 1
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Please check in logs if you see any log for your PC IP?
Please check the firewall policy to see if you have correctly configured it. https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/656084/firewall-policy
Are you using SD-WAN?
Please share the debug flow logs here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi also try doing the pcap on the lan interface for any traffic filter for that source ip to see if you are seeing any traffic coming on fortigate, and try ping to lan interface ip as well to see it is able to communicate to lan. and try the ping from fortigate to that device as well to see if it is connecting from fortigate, if the device is wndows make sure to disable firewall on that pc before trying to ping to it
