Possible Routing Problem, need help, FortiGate 30E OS: 5.6.3, Router/NAT mode
- December 22, 2017
- 1 reply
- 2970 views
Hello,
I need some help with a weird problem...
I have a customer, we need to separate his network into different zones behind a FortiGate 30E (OS: 5.6.3, Router Mode).
Please see attached file for the actual network structure.
There's this 192.168.0.0/24 network right behind the ASUS DSL-AC68U Internet Router. And, by now 2 networks behind the FortiGate.
I've configured some static route on the router and also one static route on the FG directing traffic to the router as standard gateway to I-Net.
But now there seems to be a problem:
In inconstant time intervals the clients still in 192.168.0.0/24 network have problems to connect to I-Net targets and also to targets behind the firewall. The internet connection itself is still online and after a few seconds the clients are able to connect. But connecting to targets behind the firewall does not work.
Some examples:
Pinging from laptop (wifi) to PBX (192.168.2.1) will not work, when using tracert to this target, the first two packets are dropped, the third works and target is reached. But the softphone client is not able to connect to PBX via SSL or XMPP (VOIP unable to say).
Some devices (LAN cable connected) having drop outs within the internet connection and are not connecting to other internal systems.
Sometimes I cannot connect to internal (192.168.0.0/24) devices from laptop or smartphone while in the same network but connected via wifi.
I'm almost sure that there's a routing problem.
I do not have routing protocols configured but only static routes. (at least I dont think there are any routing protocols in place).
Does one see any mistakes in this configuration?
What could I do to debug this issue?
Any hints what to try on firewall, router, clients?
Regards
Olaf