Hi all,
I have been facing the issue for a long time and couldn't resolve the issue, I thought, should share my query with you all.
let me explain first -
Let's suppose - my public IP is - 1.1.1.1 which is the LAN IP pool that is natted at the Fortigate firewall and my site is hosting with its public IP.
and ping is also allowed for this ip.
so this IP should be reachable from every location like - USA. Singapore, India, etc.
actually, I am not able to ping this from a different -2 location even my laptop as well when I am trying to ping it.
Please share your opinion.
thank you
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Umesh,
Is this IP 1.1.1.1 configured on FortiGate interface? When you do tracert from that 2 locations to 1.1.1.1, what is the last hop IP address seen? Is that last hop IP the same as the gateway IP address for FortiGate?
Best regards,
Jin
No, this IP address is the LAN ip pool which has been provided by ISP and that is natted on Fortinet firewall lets suppose -
1.1.1.1 - 2.2.2.2
why 1.1.1.1 is not reachable from outside even I have enabled ping for this policy.
and public IP always should be reachable from every location.
right.
what's your guess on this.
ok, so there is no 'real or virtual' host, or an interface that has IP 1.1.1.1 inorder to respond back, and the ippool is only used when traffic from lan to outbound is to be Nat'ed. Therefore, no response is expected.
Best regards,
Jin
Hi,
could you please execute these commands in firewall:
diag sniffer packet any 'a.b.c.d and icmp' 4 0 a (where a.b.c.d is the ip from where you are pinging your webserver public ip)
please initiate ping, check whether the packet is reaching the firewall or not and please keep us posted.
Also share us the screenshot of VIP configuration you have done in the fortigate firewall.
IP is used in ippool. VIP is not mentioned and therefore assumed not in use.
Best regards,
Jin
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1711 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.