Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
selassi
New Contributor

Fortigate 900D troubleshooting

Good day.

 

I once made a thread for this before but i felt i did not provide enough information to allow seasoned engineers to assist me. please find attached copies of the network in quetion and a Pcap capture of the traffic for your analysis.

 

Brief description

i have two fortigate 900Ds in seperate locations and a mail server that must be accessed by a third party. all these connections are through MPLS and my main problem is if i rdp into the mail server and try to ping the third party interface (not the firewall) the result is that the server can only see the gateway and drops all the other packets. the third party urgently need to connect to this server and i really dont know how to go about this. when i run the get routing-table details i get via static, distance 10, metric 0. 

 

if there is more clarification needed on top of the information i provided i am ready to provide. 

 

Kind regards

 

me

  

3 REPLIES 3
Toshi_Esumi
SuperUser
SuperUser

Still not enough info to let anybody believe it's not because of the Cisco ASA sitting in front of the mail server.

ericli_FTNT
Staff
Staff

It would be perfect if you could post another diagram with higher resolution.

selassi

I failed to send a clearer image because of upload limit so I had to compress it. basically what is happening is traffic is coming from third party  and reaching our network through MPLS from there it first gets to the FW on the console in subnet 1 then it exits through the specific third party IP and goes to the offsite DC through the MPLS again..... now that is not happening and when I tracert from the mail server to the 3rd party |IP on my FW it only gets to the gateway and drops packets what can I do to make traffic move from mail server to the specific IP? 

Labels
Top Kudoed Authors