Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dyop_Geop
New Contributor

VIP with port forwarding, allow icmp

I think this is an easy question for guys with great fortinet experience., I just can' t find any documents supporting this claim that.... IS it true that icmp/ping is not allowed when you do a Virtual IP with portforwading? Situation: example: Server inside LAN Network with private IP Address, given with its own public IP address,but only http,ssh,ping allowed access. Virtual IP: Public IP >>> Private IP - SSH(external port 22 mapped to 2200) Public IP >>> Private IP - http(external port 80 mapped to 80) how about ping? If we uncheck the portfowarding option, pings will be received.
5 REPLIES 5
ede_pfau
SuperUser
SuperUser

ICMP is only passed if TCP/UDP port forwarding is not enabled. ICMP is a different protocol. A VIP without port forwarding can even pass other IP protocols but with ports, TCP and UDP only. If you want to check a device presence, maybe you could use " TCP ping" ? I don' t know of any tool available but even in FortiOS the Dead Gateway Detections is able to use ICMP or TCP or UDP pings.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
netmin
Contributor II

A small tool: http://technet.microsoft.com/en-us/sysinternals/jj729731.aspx
MikePruett
Valued Contributor

I can ping devices but only if I have my VIP saying external IP to internal IP...not specific port forwarding.
Mike Pruett Fortinet GURU | Fortinet Training Videos
TuncayBAS
Contributor II

ping protocol 1 tcp 6 and udp 17 ping not forward inside if port forward is enabled
Tuncay BAS
RZK Muhendislik Turkey
FCA,FCP,FCF,FCSS
Tuncay BASRZK Muhendislik TurkeyFCA,FCP,FCF,FCSS
Christopher_McMullan

FortiOS v5.2.1 was released yesterday on our support site. Just FYI, one of the new features is that a VIP with port forwarding will now support ICMP (release notes p. 6 under ' Firewall' ).

Regards, Chris McMullan Fortinet Ottawa

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors