Hi!
I am trying to setup a VWire-firewall behind the perimeter routers.
Everything is working fine, except every connection that:
- traverses the VWire
- AND terminates at the firewall
In the attached picture:
--> PC 2+3 can access FG-Management-Port
--> PC 1 CANNOT access FG-Management-Port
--> PC 1 can access PC 2+3
Do you have any idea, how to avoid problems with packages, which are passing the VWire and terminating to the FG-Management-Interface?
Thank you
Regards
KPS
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
What does the policy look like for that v-wire?
Mike Pruett
Hi!
The VWire-Policy does allow everything in both directions.
If I move the VWire to another VDOM, the system is working, but that is a problem for the rest of my config.
There seems to be an issue, if the packet is traversing VWire on the way to the Layer3-interface on the same VDOM.
Regards,
KPS
Hi ,
this is a known issue , as designed.
Reason is the shared routing table within VWP. You want to access a subnet that is know in the routing table but is not allowed by means of the VWP (else VWP would kinda break as you escape from the VWP).
VWP works fine for traffic between the protected subnets.
Solution, dont use VWP if traffic need to route to the fortigate itself (within a single VDOM).
A second VDOM seperates the routing table and does not have this issue.
Regards
Consultant @ Exclusive Networks BV
Datacenter Networking and Security
FCSS EFW/SDWAN
Fortinet, HPe/Aruba, Arista, Juniper and many more
Hi!
The VWire-Policy does allow everything in both directions.
If I move the VWire to another VDOM, the system is working, but that is a problem for the rest of my config.
There seems to be an issue, if the packet is traversing VWire on the way to the Layer3-interface on the same VDOM.
Regards,
KPS
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.