Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ananth
New Contributor

Routing issue from internal port to internal lan

Hi, Please help, not sure what we missed. Network diagram of what we are trying to achieve is attached. We have an FTP Server located at our ISP premises, they have given us a fiber line to our Data Center, till now it was connected to a Windows 2008R2 Server(192.168.252.9) with Routing and Remote Access service configured, but we are frequently getting service disruption, service doesn't fail, but only a service restart rectifies issue. A static route is configured in Core Switch to route all traffic to 192.168.252.20 to 192.168.5.200(internal IP of ftp-gateway). ISP has given us the range 192.168.252.0/24 any device configured in this range can ping to 192.168.252.20. We don't have an VLAN 192.168.252.0/24 internally. Since we just replaced our old Firewall with 90E and with the additional interfaces we are trying to replicate this routing in 90E. Unfortunately we have not had any success. Below given is the overall setup. Local LAN is in 192.168.0.0/255.255.0.0 range with VLANs and all. In our Core switch we have changed the static route to route all traffic to 192.168.252.20 towards our firewall 192.168.0.250. In Firewall internal interface 10 is configured with ip 192.168.252.8 and from firewall we can ping 192.168.252.20(ftp server's internal ip). From FTP Server also we can ping firewall's ip(192.168.252.8). There is Policy route also to route traffic from internal to internal10(192.168.252.8) and from internal10 to internal lan. This is identical to the existing setup using the Windows Gateway but no success!

But we are unable to ping to our internal lan or from lan to FTP server. please advise. Thanks Ananth

v5.4.4,build6019 Fortinet 90E

Fortigate 80C v5.2.8,build727

Fortigate 100A

Fortigate 80C v5.2.8,build727 Fortigate 100A
0 REPLIES 0
Labels
Top Kudoed Authors