Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
huud
New Contributor III

Pinging Between VLANs on Different Physical Interfaces ?!

Hi,

 

I have the below setup on an ESXi host, Router VM is a Fortigate Firewall VM.

 

huud_0-1716635029268.jpeg

Traffic from VM1 can ping VM2 but not the other way around, not sure what is missing.

 

huud_0-1716635649140.jpeg

 

huud_1-1716635675785.png

 

Intergfaces configuration

 

a.JPG

 

Policies Configuration

 

b.JPG

 

vSwitch 1G is connected to vmnic0 and vSwitch 10G is connected to vmnic1.

 

Any help as to what is missing ?

 

Thank You

1 Solution
ozkanaltas
Valued Contributor II

Hi @huud,

 

Sorry for the misunderstanding.

 

Can you ping from 10.11.40.178 to 10.11.40.100?

 

Also, can you run these commands on cli while pinging from 10.11.40.178 to 10.11.40.100? Can you share the output with us?

 

 

diagnose sniffer packet any 'host 10.11.40.178' 4 a

 

 

 

diagnose debug flow filter saddr  10.11.40.178
diagnose debug flow trace start 100
diagnose debug enable

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
4 REPLIES 4
ozkanaltas
Valued Contributor II

Hello @huud,

 

Your configuration it seems okay.

 

Did you check windows firewall settings? On the first setup, windows firewall coming with deny to icmp traffic.

 

And also, can you check firewall logs from Log&Report->Forward traffic menu.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
huud
New Contributor III

Hi @ozkanaltas 

 

I'm not pinging the Windows, I'm pinging the Firewall Interface port1, it has ping allowed on it..

 

Also Forward traffic has nothing in it..

ozkanaltas
Valued Contributor II

Hi @huud,

 

Sorry for the misunderstanding.

 

Can you ping from 10.11.40.178 to 10.11.40.100?

 

Also, can you run these commands on cli while pinging from 10.11.40.178 to 10.11.40.100? Can you share the output with us?

 

 

diagnose sniffer packet any 'host 10.11.40.178' 4 a

 

 

 

diagnose debug flow filter saddr  10.11.40.178
diagnose debug flow trace start 100
diagnose debug enable

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
huud
New Contributor III

Thanks @ozkanaltas for the commands, I found that the gateway IP for 10.11.40.178 was set as 10.11.40.11 and NOT 10.11.40.100, this was corrected and is now pinging interface 10.11.30.100, and VM1 and VM2 can piung each other..

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors