I have some problem with my fortigate, I'm using Fortigate 60d. And now I have 2 ISP which is I using in wan 1 and wan 2. The problem is, I can't ping my ip public in wan 2 from the outside. But when I switch my wan 2 into wan 1, I can ping it. But still the wan 2 which is now usually I move from wan 1 still can't ping. Can you help me pls? Current Running Firmware: FGT60D-5.00-build292.
execute ping-options source x.x.x.x
execute ping x.x.x.x
Kind Regards,
IPNS
ipns wrote:sorry..the problem is I can't ping my wan 2 ip public from the outsideexecute ping-options source x.x.x.x
execute ping x.x.x.x
Is ping enabled under allow access for the WAN2 interface? Also you need a route via WAN2 to the public internet, with the same distance but lower priority. Maybe you could post your routing table in here with masked addresses: get router info routing-table all
Probably because the default route is pointing toward wan1 so your ping from outside comes in wan2 and tries going out to wan1: asymmetric route. You can allow it but would lose most of FW capabilities. Depending on how you want to utilize two internet paths you need to either split them manually per destination groups/routes, make one of them as backup, or set one of load-balancing methods.
you need have some setting and the wan2 . Could you list you wan2 setting ?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1739 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.