Hi Sir / Ma'am
I created Zone 10, 20, 30 and followed the instruction from Fortigate Cookbook using our Fortigate Firewall FG101E. I have also included myself in the address objects and created a policy going from LAN to WAN and WAN to LAN and there is still no connection. I have also checked block-intra traffic. What is wrong with my configuration? Hoping for your reply. Thanks!
Without your config and a "diag debug flow" we would have no clue as to what you're doing or what's happening. You mention zone and then stated and I quote
I have also included myself in the address objects and created a policy going from LAN to WAN and WAN to LAN and there is still no connection.
So is correct or is the policy src/dst intf vrs src/dst zone members? Please update and provide more details or topology map, but I would get a flow trace with the dst address and state to monitor the output. I would suspect based on traffic is not working its policy or routing, or address object is wrong.
Ken Felix
PCNSE
NSE
StrongSwan
Would it work without zones? Then problem is the policy. Zone just collects all member interfaces and let policies to use it instead of individual interfaces.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.