Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
afarouk
New Contributor

cant access internet using Fortigate VM

I have deployed Fortigate-VM and I am able to access the GUI.

The firewall can access the internet but as a users I can reach the firewall but no internet connection.

I would like some help if there is any configuration needed on the ESXI or the switch where its connected.

 

1 port connected for LAN and another port connected for WAN.

 

1.jpg2.jpg3.jpg4.jpg5.jpg6.jpg7.jpg

32 REPLIES 32
vbandha

Actually I made a mistake in the last reply. Please run the sniffer in CLI:

diagnose sniffer packet any 'host 8.8.8.8 and icmp' 4 0 a

 

After that ping 8.8.8.8 from one of your end devices in the 10.10.100.x network

afarouk

Forti-VM # diagnose sniffer packet any 'host 8.8.8.8 and icmp' 4 0 a
Using Original Sniffing Mode
interfaces=[any]
filters=[host 8.8.8.8 and icmp]
2023-05-07 10:23:51.645237 port1 in 10.10.100.1 -> 8.8.8.8: icmp: echo request
2023-05-07 10:23:56.172981 port1 in 10.10.100.1 -> 8.8.8.8: icmp: echo request
2023-05-07 10:24:01.160743 port1 in 10.10.100.1 -> 8.8.8.8: icmp: echo request
2023-05-07 10:24:06.162509 port1 in 10.10.100.1 -> 8.8.8.8: icmp: echo request
2023-05-07 10:24:12.321200 port1 in 10.10.100.1 -> 8.8.8.8: icmp: echo request
2023-05-07 10:24:17.161523 port1 in 10.10.100.1 -> 8.8.8.8: icmp: echo request
2023-05-07 10:24:22.175674 port1 in 10.10.100.1 -> 8.8.8.8: icmp: echo request
2023-05-07 10:24:27.161236 port1 in 10.10.100.1 -> 8.8.8.8: icmp: echo request

srajeswaran

diagnose sniffer packet any 'host 8.8.8.8 and icmp' 4 ,can you collect this for ping initiated from the firewall?

 

What is the source IP we see in the traffic initiated from Firewall, can we make sure same source IP is used in NAT for the traffic from LAN to Internet.

 

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

Labels
Top Kudoed Authors