Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tox
New Contributor II

can ping from behind fortigate but not the other way around

HI

first, take a look at this Screenshot 

 

after setting a new policy that allows ICMP, now I can ping from 192.168.20.67 to 192.168.200.24

however, I still cannot ping the other way around.

Please help me fix this issue, i have uptime Kuma monitoring server and i need to monitor many things inside the forti network 

 

Thanks you!

 

6 REPLIES 6
tox
New Contributor II

device: FortiGate 101E

v6.2.3 build1066 (GA)

Debbie_FTNT
Staff
Staff

Hey tox,

 

some additional information might be useful to determine why pings are only possible in one direction - what did you check already, did you try pings from the FortiGate directly (if yes, are they working?), what does your configuration look like?
You can check the following:
- do you have a policy for the non-working direction in place, with correct source/destination/interfaces/etc?
- does your FortiGate have appropriate routes configured/learned to be able to pass the ping?
- can your FortiGate ping the PCs in question?

#execute ping <IP>

- do you allow ping in whatever firewall is running on the PCs?

 

For basic troubleshooting on the FortiGate, you can use the following tools:

- debug flow (lets you figure out if a route is found, and a policy is matched)
https://docs.fortinet.com/document/fortigate/6.2.3/cookbook/54688/debugging-the-packet-flow

- diag sniffer (lets you confirm that traffic arrives at and exits the FortiGate)
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Using-the-FortiOS-built-in-packet-sn...


A general overview of steps you might want to follow:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connecti...


I hope that helps :)

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
tox
New Contributor II

from the CLI i can ping both PCs 

 

from the screenshot, i can send a ping from PC2 to PC1 without any problem

i cannot send a ping from PC1 to PC2 

i added a policy that allows ICMP which allowed me to ping from PC2 to PC1 

does your FortiGate have appropriate routes configured/learned to be able to pass the ping?

i added the policy to all interfaces to allow ICMP 

 

from the links you sent i tried to investigate as much as i could, my knowledge is limited in FortiGate 

 

 

AlexC-FTNT

the policy is allowing or blocking the traffic. It does not replace routing.
First check: make sure that the correct routing is in place:

"get router info routing-table detail 192.168.20.67"  should show the port towards PC2
"get router info routing-table detail 192.168.200.24"  should show the port towards PC1


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
Debbie_FTNT

You can try a traceroute command from PC1 to PC2, to see where it fails, and verify that it actually fails at the FortiGate and not anywhere else.
Aside from that, I can only really recommend sending a ping, and having 'debug flow' commands running at the same time to see what FortiGate does with the pings.
You can also open a Technical Support case (if your FortiGate has support coverage) if you are looking for more in-depth guidance or a remote session.

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
tox
New Contributor II

ok so, I don't want to ping anything on this planet AT ALL, I ended up breaking the whole network, 2 FortiGate  101E 12 fortiAP, and basically the whole thing,by mistake of course:DD

I spent a good 25 hours fixing everything with my whole team

i will never ping anything ever again ever.

 

Thank you all for your help 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors