Hi,
I have the below setup on an ESXi host, Router VM is a Fortigate Firewall VM.
Traffic from VM1 can ping VM2 but not the other way around, not sure what is missing.
Intergfaces configuration
Policies Configuration
vSwitch 1G is connected to vmnic0 and vSwitch 10G is connected to vmnic1.
Any help as to what is missing ?
Thank You
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Created on 05-25-2024 04:41 AM Edited on 05-25-2024 04:42 AM
Hi @huud,
Sorry for the misunderstanding.
Can you ping from 10.11.40.178 to 10.11.40.100?
Also, can you run these commands on cli while pinging from 10.11.40.178 to 10.11.40.100? Can you share the output with us?
diagnose sniffer packet any 'host 10.11.40.178' 4 a
diagnose debug flow filter saddr 10.11.40.178
diagnose debug flow trace start 100
diagnose debug enable
Hello @huud,
Your configuration it seems okay.
Did you check windows firewall settings? On the first setup, windows firewall coming with deny to icmp traffic.
And also, can you check firewall logs from Log&Report->Forward traffic menu.
Created on 05-25-2024 04:23 AM Edited on 05-25-2024 04:29 AM
Hi @ozkanaltas
I'm not pinging the Windows, I'm pinging the Firewall Interface port1, it has ping allowed on it..
Also Forward traffic has nothing in it..
Created on 05-25-2024 04:41 AM Edited on 05-25-2024 04:42 AM
Hi @huud,
Sorry for the misunderstanding.
Can you ping from 10.11.40.178 to 10.11.40.100?
Also, can you run these commands on cli while pinging from 10.11.40.178 to 10.11.40.100? Can you share the output with us?
diagnose sniffer packet any 'host 10.11.40.178' 4 a
diagnose debug flow filter saddr 10.11.40.178
diagnose debug flow trace start 100
diagnose debug enable
Created on 05-25-2024 04:51 AM Edited on 05-25-2024 04:51 AM
Thanks @ozkanaltas for the commands, I found that the gateway IP for 10.11.40.178 was set as 10.11.40.11 and NOT 10.11.40.100, this was corrected and is now pinging interface 10.11.30.100, and VM1 and VM2 can piung each other..
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1517 | |
1018 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.