Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
freaky
New Contributor

Ping server down -> generate alert

Hi there, kind of surprised the standard alert options don' t send an email when one of the pingservers (and thus a connection) goes down. Currently we have several customers with 2 wan connections. The connections use different infrastructure providers, so a disruption in the infrastructure with one provider doesn' t take down both lines. Anyways we ping the DNS servers of the ISP on the line. This usually is sufficient to detect if a line is working. However, when the ping server becomes unavailable no alert is generated. Anyone know how we can be alerted when a line goes down? In any way btw... if the link to the modem goes down I' d like to know too, but mainly I only care about the ping server dying. If the link goes down, that will go down too. Anyways really curious about this one. Oh, and is there a way to see a line is down (by ping server unavailable) from CLI? Currently one of the lines is down (my policy route over wan2 for 25 is also dead as 25 connections now nicely go over wan1 as intended), however, CLI reports: FGT50B<serial> # get system interface == [ internal ] name: internal mode: static ip: 172.16.255.254 255.255.0.0 status: up netbios-forward: disable type: physical mtu-override: disable == [ wan2 ] name: wan2 mode: dhcp ip: w.x.y.z 255.255.252.0 status: up netbios-forward: disable type: physical mtu-override: disable == [ wan1 ] name: wan1 mode: static ip: w.x.y.z 255.255.255.248 status: up netbios-forward: disable type: physical mtu-override: disable Appearantly only the route is removed... One more kind of issue is DNS in these setups. Usually it' s much faster to use forwarding DNS servers. However, ISP' s usually only allow forwarding from their accounts. This is kind of an issue. Besides the entire LAN slowing down when the main line goes down, due to using wrong DNS servers, the fortigate has the same issue, and the fortigate itself can' t be policy routed nor s/dnat' ed.
4 REPLIES 4
rwpatterson
Valued Contributor III

Setting the ISPs DNS server...won' t it still ping through the backup line? Try setting the ping server to the next hop router (hopefully not dynamic DNS...).

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
freaky
New Contributor

Don' t quite get the reply. Fortigates have the option to enter a ping server in the interface settings (where you also set the IP, netmask, etc). So no, if the line goes down it won' t ping it through the other line, it' s only used to monitor if that interface is functioning properly. If the ping server isn' t reachable through that interface it removes the routes associated with the interface. This will cause any policy routes using it to go void and automatically switch to the other line. If that happens it means the line is no longer usable. So we want to know that. Usually an ISP/internet connection failure will resolve itself in a while. But we still like to know it' s down. Btw. pinging the router is a bad idea in this situation. It could very well be that the DSL line dies, in which case the router is still perfectly available.
rwpatterson
Valued Contributor III

OK I get the ping server thing, but if the DSL line goes down, isn' t it the same? The interface by all intents and purposes can' t do anything? Pinging the external interface would serve the purpose. If the line dies, the WAN IP would go down, and voila!

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
freaky
New Contributor

Not always, several ISP' s, mainly those with Cisco' s and a static subnet, have the IP' s hardcoded into the device (here atleast..). The logging does have the device tho' , you just need to turn on the detail' s column, which is off by default. Also, we can get the e-mails, we have to turn on the notification by alert level and set it to warning or lower, so it' s solved (albeit this might generate much more than just the intended e-mails). Anyways, thanks for the re' s.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors