I have a FortiGate 50E with a FortiSwitch 124E-FPOE
I have a client subnet on the switch with my clients, a NAS and a printer
In addition, i have a vlan for VoIP and IPSec VPN
I can ping across all all Subnets, but not within the client subnet. e.g. client to printer
I can ping from outside the client subnet (from Wlan, from IPSec etc) to the NAS and the printer
I can ping from my client subnet to all other subnets
But I can not ping from the client subnet to other systems in the client subnet.
What do i need to change?
Solved! Go to Solution.
could it be possible you have enabled Access VLAN on your Client VLAN?
Fortigate 500E HA Fortimail 200 Fortimanager
FortiEMS
FortiSandbox 1000D
FortiSwitch Network Some other Models in use :-) ---------------------------------------------------- FCSE ----------------------------------------------------
Hello
Please check your policies and pbr rules on fortigate. it seems ttaht there is problem is regarding Forti-switch
could it be possible you have enabled Access VLAN on your Client VLAN?
Fortigate 500E HA Fortimail 200 Fortimanager
FortiEMS
FortiSandbox 1000D
FortiSwitch Network Some other Models in use :-) ---------------------------------------------------- FCSE ----------------------------------------------------
I don't really understand:
The Clients are in the same Subnet, so there wont be any routings / policies?
that's the way I know it. Client to Client in the same subnet does not even reach the firewall because the client has a route for that subnet as it has an interface in it. It does not matter if this is a vlan interface or a physical one.
Only traffic that leaves the client's subnet will hit the default gw.
So I would point to your (Forti)Switch. Maybe it has somethink linke port isolation or similar that prevents ne port from reaching annother (Except from the uplink to the FGT).
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
I've now disabled "access VLAN" and now it works
Many thanks!
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.