Hello Experts,
I created policy for LAN to WAN rule with open port 80,443. One of our user was accesing website "https://in.pinterest.com/" but it is unable to connect . WHY ?
But when i am select "ALL" in services then it is opening. I want to know that which particular port or service need to add in "Service" option. so that user can access this website.
KS
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
1>What service did you define in the fwpolicy?
2>Did you execute and diag debug flow to see if it was matching that fwpolicy ( by policy-id)
3>and to go along with #2, did you validate the fwpolicy sequence and ordering ?
PCNSE
NSE
StrongSwan
emnoc wrote:1>What service did you define in the fwpolicy?
2>Did you execute and diag debug flow to see if it was matching that fwpolicy ( by policy-id)
3>and to go along with #2, did you validate the fwpolicy sequence and ordering ?
Hello Emnoc,
1. http =80 and https=443
2. this command is not showing any logs, how to perform this task
3. how can we validate Sequence and ordering
ift38375 wrote:
2: this command is not showing any logs, how to perform this task 3. how can we validate Sequence and ordering
For #2, search for diag debug flow you have many filter options apply a filter to match the traffic port src or dst and review the diagnostic output. If it matches the firewall policy than inspect the firewall policy, if it doesn't match the specific firewall policy than determine why ( routing, some other external issues )
For #3; I prefer the cli but the webgui shows the same thing with regards to the ordering of policies
If the policy sequence is nor correct , move it around to ensure the most specific are place before a broader fwpolices.
lastly, double check for any NAT issues if the client src is an rfc1918 addressed.
PCNSE
NSE
StrongSwan
@ift38375
Also does this problem happen from all web browsers?
And have you tried to access the website from another computer?
Any UTM features enabled on that firewall policy?
Nslookup (using www.kloth.net) reports in.pinterest.com resolves to:
Non-authoritative answer:
in.pinterest.com canonical name = www.pinterest.com.
www.pinterest.com canonical name = www.pinterest.com.edgekey.net.
www.pinterest.com.edgekey.net canonical name = e9343.a.akamaiedge.net.
Name: e9343.a.akamaiedge.net
Address: 172.227.88.170
You have anything in place that is blocking any of those addresses?
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.