- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Problem with Policy
Hello,
I have two networks connected to port1 and port 16 on my FG100. I want connect from Port1 to Port16 .
I can't ping any address in this network.
config of my port 16
edit "port16"
--More-- set vdom "root"
--More-- set ip 172.100.x.2 255.255.255.0
--More-- set allowaccess ping https http fgfm capwap
--More-- set type physical
--More-- set alias "MGMT_LAB"
--More-- set device-identification enable
--More-- set snmp-index 4
--More-- next
config my port 1
edit "port1"
--More-- set vdom "root"
--More-- set ip 172.17.x.1 255.255.255.0
--More-- set allowaccess ping https ssh snmp
--More-- set type physical
--More-- set netflow-sampler both
--More-- set alias " LAN"
--More-- set device-identification enable
--More-- set device-identification-active-scan enable
--More-- set snmp-index 11
--More-- set secondary-IP enable
--More-- config secondaryip
--More-- edit 1
--More--
--More-- set allowaccess ping
--More-- next
--More-- end
config of my policy
edit 40
--More-- set name "MGMTto LAB"
--More-- set uuid 48e6f806-ad20-51e9-08e5-b0363071ad14
--More-- set srcintf "port1"
--More-- set dstintf "port16"
--More-- set srcaddr "LAN 172.16.0.0"
--More-- set dstaddr "all"
--More-- set action accept
--More-- set schedule "always"
--More-- set service "ALL"
--More-- set logtraffic all
--More-- set timeout-send-rst enable
--More-- next
Log for this policy
Date07/23/2019Time15:23:32Duration75sSession ID37486893Virtual Domainroot
SourceIP172.16.0.61Country/RegionReservedPrimary MACfxxxSource Interfaceport1Host NamexxxDevice TypeWindows PCOS NameWindows MEUnauthenticated Userxxx$Unauthenticated User SourcekerberosUser
xxx$
DestinationIP172.101.0.1Host NamexxxCountry/RegionUnited StatesDestination Interfaceport16
ApplicationApplication NamePINGCategoryunscannedProtocolicmpServicePING
DataReceived Bytes0 BReceived Packets0Sent Bytes240 BSent Packets4
ActionActionAcceptPolicy40Policy UUID48e6f806-ad20-51e9-08e5-b0363071ad14Policy Typepolicy
SecurityLevel
OtherSource Interface RoleundefinedLog ID13byod_nameskypewawaProtocol Number1roll64317byod_devicewindows-pcLog event original timestamp1563888212Destination Interface Roleundefineddstcountry_codeUSSource Server0Sub TypeforwardSecurity Events[]
Should I configure some else ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
1. you source address at the policy is not part of the source interface.
2. the source address is a network address not a host address.
3. you might need to configure also the reverse policy
4. at the policy config you say port 1 to port 16 (lab to mgmt) but you named the policy mgmt to lab. (this is not misconfiguration but it doesnot look right
Orestis Nikolaidis
Network Engineer/IT Administrator
