Dear Sir,
We have a almalinux server running a website. This server has a dedicated Public IP.
We want to change its private IP address from 192.168.3.A to 192.168.3.B.
Before changing the private IP, we have duplicated all relate Fortigate firewall policies for the new IP 192.168.3.B.
However, we found that we still cannot connect the website after changing the private IP.
The sever is connected to the internet because we can ping outside from the server, and we can also ping the server from other computer in the same subnet. We feel the problem is due to the firewall policy but we don't know where it is.
Can anyone advise us what settings can cause this problem?
Thank you.
Hi
Did you change the VIP as well?
Yes, I have changed VIPs in the duplicated policies.
But did you remove the old VIPs. If you keep them then they will still map to the old IP:Port.
On the other hand, try run the debug flow command and share the output to see if the traffic is correctly mapped and if it is blocked by some rule.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Debug-flow-tool/ta-p/213238
Hi
I tried to run the debug flow command at a live site but I didn’t see any output .
Can you provide any example of running the debug flow tool?
Thank you
Hi
You can follow the CLI example provided in this tech tip.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Debug-flow-tool/ta-p/213238
Hi @YHC ,
1) Run "get sys arp" on FGT to confirm whether you see "192.168.3.B" or not;
2) If not, please confirm whether you Ping 192.168.3.B from FGT or not:
exe ping 192.168.3.B
3) Please confirm whether 192.168.3.B can Ping FGT or not;
User | Count |
---|---|
2547 | |
1354 | |
795 | |
644 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.