Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
exec traceroute 207.109.53.142I think it goes out over one of the other connections:
IASLC-FW01 # exec traceroute 207.109.53.142 traceroute to 207.109.53.142 (207.109.53.142), 32 hops max, 72 byte packets 1 207.225.112.2 <hlrn-dsl-gw02.hlrn.qwest.net> 38.313 ms 37.918 ms 39.709 ms 2 71.217.188.13 <hlrn-agw2.inet.qwest.net> 37.788 ms 37.658 ms 37.722 ms 3 67.14.24.17 <dvr-core-01.inet.qwest.net> 38.925 ms 39.289 ms 39.080 ms 4 67.14.24.93 <dvr-edge-13.inet.qwest.net> 38.596 ms 38.563 ms 38.373 ms 5 * * * ...
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
ORIGINAL: BraddyJ Yes, NAT is checked and using destination interface IP address in all outbound rules. Correct me if I' m wrong, but I shouldn' t even need a rule to be able to ping 1 hop beyond my default gateway from the firewall console, right?You are correct. I missed the console part of the post. Perhaps you need to set the ping options in the unit to use the IP associated with that port...
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
PCNSE
NSE
StrongSwan
Yes, NAT is checked and using destination interface IP address in all outbound rules.Is Port15 showing any traffic at all? Duplex/speed set to auto or forced? (" debug hardware deviceinfo nic port15" ) Any router policy configured? Considering all routes being equal, wouldn' t the fgt pick either the lowest port# or use odd/even, etc. when choosing a route path?
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.