Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jtfinley
Contributor

Ping out no DNS out?

Ive seen this issue a couple times, where users behind a Fortigate can ping, but suddenly cannot surf web as if DNS is not resolving. I know DNS is fine, and the Fortigate is reachable remotely. Once the Fortigate is recycled, browsing is fine. I' m assuming it' s a proxy problem, any ideas?
15 REPLIES 15
jtfinley

Same issues with FG 60 models. If I uncheck " protection profiles" under the policy that allows users out to the internet, users will be able to surf. I do not want to " Uncheck Protection Profiles" so I resboot and all works for a day or 2 and then Internet breaks again.
Do you have any AV or IPS blocking if something is triggered? I had something like this. In my case, there are no IPS settings in my policy that are enabled.
Not applicable

None that I can see, it has happened on different FG firewalls at different times. Users cant access internet, reboot firewall fixes issue for a couple of weeks and it happens again.
jtfinley

None that I can see, it has happened on different FG firewalls at different times. Users cant access internet, reboot firewall fixes issue for a couple of weeks and it happens again.
Ive had this happen on two Fortigates of different models, and it' s consistent to the same environment meaning, I only have this issue at two places not all over.
Not applicable

It is becoming ridiculous and I am surprised Fortinet has no fix out for that.
jtfinley

Following up on this one. We' ve had (2) instances where a Fortigate WIFI 30 & 80c would literally go offline. The INTERNAL interface is not pingable nor the WAN, however, connected to the console, I can ping various hosts on the Internet, but not internally. I set my ping-option sourced from internal IP and executing a ping from Fortigate fails. This one has me stumped. Nothing has changed in the configs for weeks. Both were running MR3
jtfinley

Another follow up here. Previously stated there were (2) instances happening, I have eliminated one. It turned out to be an issue with the managed ISP filtering inbound somehow. The other item, we downgraded/firmware flash to MR2p8. No issues since. --Joe
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors