Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CAD
Contributor

how to solve this problem

Hi all, I have software for shipment from "Fedex", i had installed in my PC , and fedex team support provide me some public IP to allow in my firewall in order to allow this software to connect the server, i have allowed this IP and created policy and i kept in top the software worked fine for a few weeks , now i getting the following error when open software"Cant Download File //app/lib/zip.jar" i called the Fedex team support for this issue they are tolled me this problem from my firewall.

 

how to trace this issue and how to resolved.

 

Thanks 

3 REPLIES 3
emnoc
Esteemed Contributor III

Suggestion:

 

[ul]
  • diag debug flow would be the 1st step.[/ul]

     

    [ul]
  • review of the security settings and inspections for that SRC[/ul]

     

    [ul]
  • a temporal fwpolicy set just for that site with n UTM fetaures for testing[/ul]

     

     

    Ken

  • PCNSE 

    NSE 

    StrongSwan  

    PCNSE NSE StrongSwan
    CAD

    Thank you emnoc for reply,

     

    I have disabled UtM feature in FwPolicy,and please check result for diagnose debug:

    It seem that only IP address response.

    FG200D # execute ping 199.81.216.xx PING 199.81.216.xx (199.81.216.xx): 56 data bytes 2017-05-25 16:43:31 id=20085 trace_id=6 func=print_pkt_detail line=4478 msg="vd- root received a packet(proto=1, 94.243.xx.XX:3328->199.81.216.xx:8) from local . code=8, type=0, id=3328, seq=0." 2017-05-25 16:43:31 id=20085 trace_id=6 func=init_ip_session_common line=4631 ms g="allocate a new session-042d0005" 2017-05-25 16:43:32 id=20085 trace_id=7 func=print_pkt_detail line=4478 msg="vd- root received a packet(proto=1, 94.243.XX.XX:3328->199.81.216.xx:8) from local . code=8, type=0, id=3328, seq=256." 2017-05-25 16:43:32 id=20085 trace_id=7 func=resolve_ip_tuple_fast line=4541 msg ="Find an existing session, id-042d0005, original direction" 2017-05-25 16:43:33 id=20085 trace_id=8 func=print_pkt_detail line=4478 msg="vd- root received a packet(proto=1, 94.243.XX.XX:3328->199.81.216.58:8) from local . code=8, type=0, id=3328, seq=512." 2017-05-25 16:43:33 id=20085 trace_id=8 func=resolve_ip_tuple_fast line=4541 msg ="Find an existing session, id-042d0005, original direction" 2017-05-25 16:43:34 id=20085 trace_id=9 func=print_pkt_detail line=4478 msg="vd- root received a packet(proto=1, 94.243.XX.XX:3328->199.81.216.xx:8) from local . code=8, type=0, id=3328, seq=768." 2017-05-25 16:43:34 id=20085 trace_id=9 func=resolve_ip_tuple_fast line=4541 msg ="Find an existing session, id-042d0005, original direction" 2017-05-25 16:43:35 id=20085 trace_id=10 func=print_pkt_detail line=4478 msg="vd -root received a packet(proto=1, 94.243.XX.XX:3328->199.81.216.xx:8) from loca l. code=8, type=0, id=3328, seq=1024." 2017-05-25 16:43:35 id=20085 trace_id=10 func=resolve_ip_tuple_fast line=4541 ms g="Find an existing session, id-042d0005, original direction"

    --- 199.81.216.xx ping statistics --- 5 packets transmitted, 0 packets received, 100% packet loss

    FG200D # execute ping 199.81.216.xx PING 199.81.216.xx (199.81.216.xx): 56 data bytes

    --- 199.81.216.xx ping statistics --- 5 packets transmitted, 0 packets received, 100% packet loss

    FG200D # execute ping 204.135.13.xx PING 204.135.13.xx (204.135.13.xx): 56 data bytes

    --- 204.135.13.xx ping statistics --- 5 packets transmitted, 0 packets received, 100% packet loss

     

    emnoc
    Esteemed Contributor III

    No you need the application running during the diag debug flow trace. A imp echo/replay is no good for this diagnostics.

     

     

    Suggestion:

     

    have you reviewed any logs ( client2server  or server2client )? 

    What happening at the fedex software ( auth failure, failure to connect? etc...)

    PCNSE 

    NSE 

    StrongSwan  

    PCNSE NSE StrongSwan
    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors