Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
minhthanh114
New Contributor II

I can't connect to IP on the interface.

Dear All,

I'm using the FortiGate 100D and I am using 802.3ad Aggregate interface. One another device is plugged into another port of the FortiGate (port 3) (IP static is 10.199.139.200). I have created one policy for I can go to that port 3 but I can't ping to the IP 10.199.139.200 when I'm in the 802.3ad Aggregate interface network. I can ping that IP from FortiGate. I don't why? 

1 Solution
minhthanh114

Dear, 

Thank' a lot, maybe I will research again.

View solution in original post

14 REPLIES 14
srajeswaran
Staff
Staff

Can you collect "diag sniffer packet any "host 10.199.139.200" 10, from Fortigate while you try to ping from the aggregate interface network? This will help us to confirm if the packet is reaching fortigate or not and then decide further torubleshooting steps.

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

minhthanh114

Dear srajeswaran,

How I can send you packet-capture.pcap file, I'm new member.

srajeswaran

I don't think you can attach it, can you take a screenshot and paste it?

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

minhthanh114

Dear,

You mean this one?

screenshot_1709013933.png

 

srajeswaran

yeah, on this one I see ICMP from 10.199.139.200 to 10.199.139.1, similarly , can you capture when you try to ping 10.199.139.200 ?

 

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

minhthanh114

Dear Mr,

That is the capture from FortiGate while I ping from the aggregate interface network. This is capture from Wireshark software while I ping from the aggregate interface network to "10.199.139.200".

222.png

 

srajeswaran

Open fortigate CLI as below and run " diag sniffer packet any "host 10.199.139.200" 10 "

This will confirm if the ICMP packet from your PC is reaching the firewall or not.

 

image.png

 

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

minhthanh114

Send to you,

 

33.png

srajeswaran

We don't see the packet from 10.199.129.149 reaching Fortigate.


is this the simple topology?
(10.199.139.200)Port3 [FortiGate]Aggregate---------------------PC(10.199.129.149)

Can you confirm the Ip/subnet mask for your PC, port3, aggregate interfaces.

Regards,

Suraj

- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

Labels
Top Kudoed Authors