Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FortinetBeginner
New Contributor III

Websites are not loading - Fortigate 120g

Hello everyone,

 

We are using a Fortigate 120g. However, we can't open any website.

 

Ping and DNS works on the client and on the fortigate and the packets are forwarded on the fortigate without dropping any packets.

 

When we connect directly to the Fortigate 120g, we can access the Internet and open web pages without any delay.

 

When we disconnect the Fortigate 120g and connect our old firewall, everything works fine right away.

 

What we tried:

Configuring port speed 1000Full on our Cisco CL9200 switch and on the Fortigate 120g.


Do you have any idea how we can fix the problem?

 

Thank you in advance!

 

Best regards

1 Solution
FortinetBeginner
New Contributor III

Ok, we fixed the problem.

It was a DNS problem.

Ping worked and DNS names were resolved, but web pages did not load.

With public DNS servers on the client, the sites loaded without delay.

With our internal DNS servers, the sites did not load.

This problem was caused by a subnet that was configured on the Mgmt port on the firewall.

This subnet overlapped with our internal DNS server subnet.

 

We found this out by performing the following steps:

 

Ping from firewall to internal DNS server works.

Ping from DNS server to firewall didn't work.

nslookup www.google.com internal DNS server

like nslookup www.google.com 172.1.1.10 (we got two timeouts before the DNS name was resolved)

 

I hope this solution helps someone.

 

 

Regards

Ralf

View solution in original post

36 REPLIES 36
salemneaz
Staff
Staff

 Please check the Following from the Firewall CLI.

 

exec ping www.google.com 

 

Check the Policy if you have enabled webfilter and the Licenses are active. Check the routing table.

 

Follow the article Reference after you run the above diagnostics steps

 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-website-is-not-reachable/ta-p/210201

Salem
FortinetBeginner

Hi Salem,

 

 

DNS works fine, but Troubleshoot-2 from your link shows only ICMP packets, but no TCP/443 packets. (See attachment).Troubleshoot-2-Result-only-ICMP-traffic.png

Ralf

 

salemneaz

from the Firewall GUI can you do this 'exec ping www.google.com'

 

Salem
salemneaz

share the output for "config system dns" then show full

Salem
FortinetBeginner

DNS-Settings-Fortigate.png

Ralf

salemneaz

share the output as well

exec ping www.google.com

from the Firewall CLI

Salem
salemneaz

do this 

config system dns

set protocol cleartext

end

 

 

Salem
FortinetBeginner

ok, done.

FortinetBeginner

Yes, I can ping www.google.comPing.png

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors