Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ift38375
New Contributor

Services under Firewall Policy not working

Hello Experts,

I created policy for LAN to WAN rule with open port 80,443. One of our user was accesing website "https://in.pinterest.com/" but it is unable to connect . WHY ?

 

But when i am select "ALL" in services then it is opening. I want to know that which particular port or service need to add in "Service" option. so that user can access this website.

 

 

KS

4 REPLIES 4
emnoc
Esteemed Contributor III

1>What service did you define in the  fwpolicy?

 

2>Did you execute and diag debug flow to see if it was matching that fwpolicy ( by policy-id)

 

3>and to go along with #2, did you validate the fwpolicy sequence and ordering ?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ift38375
New Contributor

emnoc wrote:

1>What service did you define in the  fwpolicy?

 

2>Did you execute and diag debug flow to see if it was matching that fwpolicy ( by policy-id)

 

3>and to go along with #2, did you validate the fwpolicy sequence and ordering ?

Hello Emnoc,

 

1. http =80 and https=443

2. this command is not showing any logs, how to perform this task

3. how can we validate Sequence and ordering

emnoc
Esteemed Contributor III

ift38375 wrote:

 

2: this command is not showing any logs, how to perform this task 3. how can we validate Sequence and ordering

 

For #2, search for diag debug flow you have many filter options apply a filter to match the traffic port src or dst and review the diagnostic output. If it matches the firewall policy  than inspect the firewall policy, if it doesn't match the specific firewall policy than determine why ( routing, some other external issues )

 

 

For #3; I prefer the cli but the webgui  shows the same thing with regards to the ordering of policies

 

If the policy sequence is nor correct , move it around to ensure the most specific are place before a broader fwpolices.

 

lastly, double check for any NAT issues if  the client src is an rfc1918 addressed.

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Dave_Hall
Honored Contributor

@ift38375

 

Also does this problem happen from all web browsers? 

And have you tried to access the website from another computer?

Any UTM features enabled on that firewall policy?

 

Nslookup (using www.kloth.net) reports in.pinterest.com resolves to:

 Non-authoritative answer:
 in.pinterest.com canonical name = www.pinterest.com.
 www.pinterest.com canonical name = www.pinterest.com.edgekey.net.
 www.pinterest.com.edgekey.net canonical name = e9343.a.akamaiedge.net.
 Name: e9343.a.akamaiedge.net
 Address: 172.227.88.170

 

You have anything in place that is blocking any of those addresses?

 

 

 

 

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors