So i have been trying to get one external ip for a VPN tunnel but having phase one issues
So i removed all tunnel settings/static route and addresses
I went to firewall CLI and did a execute ping and it got all responses
then did a traceroute and noticed:
TEST # execute traceroute 204.1.1.1 traceroute to 204.1.1.1 (204.1.1.1), 32 hops max, 3 probe packets per hop, 72 byte packets 1 204.1.1.1 0.544 ms 0.274 ms 0.177 ms
how is this possible to only show itself?
I can easily change last digit to .2 or even do 8.8.8.8 and i get a full hop list
But why does this one ip not give proper hops?
I think this is also possible why my VPN has issues when i do set it up
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Please explain where 204.1.1.1 lives. If it resides on the FGT(?) on the opposite side, the tunnel is likely still up. "get vpn ipsec tun sum" would tell you if it's up or down.
204.1.1.1 is in another US state. The tunnel does not exist anymore, i deleted all references to it
get vpn ipsec tun sum does not show the VPN anymore
There is something you are missing. 204.1.1.1 does not PING on the public Internet, so it is connected with your Fortigate somehow.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
run the below command to see if you that ip address configured on your firewall
show | grep -f 204.1.1.1
Based on the latency, it's not on the local FGT but a device locally connected. I would start chasing down along the interface in default route direction by checking its MAC address. Chances are one of local devices has this IP configured by accident or something.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.