Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Remko_Oude_Elferink
New Contributor

Routing issue

Hi, I have a cluster of 2 Fortigate 600C in A-P mode. MR3 P10 Running in NAT mode.. Last week i redesigned my internel network. Now we have the following design Port1 DMZ Port2 Internet Port 4 WAN (Leased line to MPLS) Port 15-18 Aggregate running VLAN100 and 107. I have 2 issues since the change.. 1. One host on the VLAN100 subnet cannot ping 1 host on the WAN. Every other host in the VLAN 100 can ping that certain host.. Checked rules but even an any to any rule does not give a solution.. 2. I cannot ping my MPLS router from VLAN 100 and 107. (I can ping it from the firewall or a WAN site.) also here an any to any rule with all services allowed.. Any Help?? Or troubleshooting ideas??
3 REPLIES 3
ede_pfau
SuperUser
SuperUser

For the first issue: Start a sniffing session on the FGT console or an ssh terminal window to see if the FGT ' sees' the pings. Watch the internal interface and the WAN port 4 to see egress traffic. I suspect that the gateway setting on this particular host is incorrect. Or, there might be static routes installed pointing to the wrong router. For the second issue: do you have policies from the VLAN interfaces to port4? Test with ANY service first. The policy from internal to port4 will not suffice.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Remko_Oude_Elferink
New Contributor

Gateway is set correct.. I do have 1 policy... Any to Any and ALL allowed.. Back and forward.. So it is wide open.. It is our monitoring system that cannot ping certain hosts.. no firewall installed locally.. His own ip adres is 172.16.100.34 FW adres on MPLS Interface is 10.1.0.2 MPLS routers has ip 10.1.0.5 and 10.1.0.6 HSRP of the routers is 10.1.0.1 I can ping from every host in the 100 and 107 range the following addresses 10.1.0.1 10.1.0.2 10.1.0.5 I cannot ping 10.1.0.6 From the firewall i can ping all 4 addresses. If i ping to 10.1.0.6 from a host than i dont see packets coming in.. Very strange..
ede_pfau
SuperUser
SuperUser

" cannot ping" can have 4 root causes: a. ping are not sent to FGT b. pings are not crossing the FGT c. pings are not replied to d. reply pings are discarded by FGT all of which can be determined by sniffing. Are you familar enough with the FortiOS CLI?

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Labels
Top Kudoed Authors