Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
biltjc
New Contributor

Unable to contact a host in another zone

Hello, I try to ping a host (1.1.1.1) from a zone (ZoneA) to another host (2.2.2.2) in another zone (ZoneB) without success. When I sniff trafic, I see this : FW_INT_01 (root) # diagnose sniffer packet any ' src 1.1.1.1 and dst 2.2.2.2' 4 interfaces=[any] filters=[src 1.1.1.1 and dst 2.2.2.2] 1140.170916 ZoneA in 1.1.1.1.500 -> 2.2.2.2.500: udp 384 1140.170940 ZoneB out 1.1.1.1.500 -> 2.2.2.2.500: udp 384 1140.170941 port23 out 1.1.1.1.500 -> 2.2.2.2.500: udp 384 1142.170404 ZoneA in 1.1.1.1.500 -> 2.2.2.2.500: udp 384 1142.170410 ZoneB out 1.1.1.1.500 -> 2.2.2.2.500: udp 384 1142.170411 port23 out 1.1.1.1.500 -> 2.2.2.2.500: udp 384 1°) what is an ip.500 ? 2°) why port23 come in the trafic ? When I make a sniff wit ha good connection I see this : FW_INT_01 (root) # diagnose sniffer packet any ' src 1.1.1.1 and dst 3.3.3.3' 4 interfaces=[any] filters=[src 1.1.1.1 and dst 3.3.3.3] 5.524581 ZoneA in 1.1.1.1 -> 3.3.3.3: icmp: echo request 10.458088 ZoneA in 1.1.1.1 -> 3.3.3.3: icmp: echo request 15.455690 ZoneA in 1.1.1.1 -> 3.3.3.3: icmp: echo request 20.452812 ZoneA in 1.1.1.1 -> 3.3.3.3: icmp: echo request
3 REPLIES 3
Mark_Oakton
Contributor

Hi, You have icmp enabled between the interfaces on a policy and you have NAT disabled? Do you have logging on the policy and what does it show in the traffic logs? Mark
Infosec Partners
Infosec Partners
Christopher_McMullan

Do you have an IPsec VPN configured? Port 500 is IPsec traffic.

Regards, Chris McMullan Fortinet Ottawa

biltjc
New Contributor

Hello,

 

Sorry for the late delay, I had a lot of things to finish.

I've done mistake in my logs capture, in red it was another service working and port 23 is the firewall VLAN trunk.

I've found the problem, no trafic is going out from the server interface to that other machine (found with Wireshark).

We suppose it is a virtual machine problem.

System team is searching the problem.

 

Thanks a lot for your help.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors