Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AbdullahMohamed
New Contributor

RADIUS and Relay

Hello I have a Fortigate connected to 3 FortiSwitches and every switch is connected to about 7 FortiAP, Now I am using WPA2 Enterprise with RADIUS and incoming Vlan ID attribute , so when client access my ssid with uname and password its automatically assigned to his vlan , my problem is when i created a vlans under my ssid I am using a dhcp relay , every client is automatically take his vlan and also my dhcp assign him the ip , but when i ping the gateway which is the vlan ip it self the ping request is time out ! , and i could not ping the dhcp itself from the client pc , however i can ping it from fortigate with source ip the vlan ip ( which is the gateway) can some one help ! Is it a bug or something ? No policies yet ( its a public policy with any any allow all ) and static default route to my p2p connection .
7 REPLIES 7
lobstercreed
Valued Contributor

It sounds to me like everything is working properly; what is the problem exactly?  Pings are not necessary.  Can you not reach the Internet? 

 

Firewalls typically don't respond to pings (making sure it responds is more complicated than I want to get into here - admin access, trusted hosts, local-in, etc), and if you don't have a policy allowing the clients to ping the DHCP server then that would be why they can't ping it.

AbdullahMohamed

Thank you for reply , My exact problem is I can not reach any HQ servers including dhcp server not only ping , and according to your comment you said that FW usually doesn't reply to ping , however I have another internal vlan with internal dhcp and i can ping FW IP normally ! Why I can not ping it from the dynamic assigned Vlans with Relay dhcp ? Also as I said i can ping my hq servers from Fortigate itself with source ip the gateway of the clients ( the interface vlan itself ) , and my policy is ( from any source interface and any address to any destination interface and any address with any service allowed without any profiles applied ) That is my problem its totally un-logic so i am confused dear .
emnoc
Esteemed Contributor III

did you run "diag debug flow" what doe it tell you in the output ?

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
AbdullahMohamed

No , I made a packet capture and i saw that the ping packets has no response , let me check diag debug flow Abdullah
emnoc
Esteemed Contributor III

routing or rule allowance from the reverse direction ?

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
AbdullahMohamed

Hello All I finally solved the problem it was just enabling DTLS to solve the vlan tagging and connectivity issue Thank you
TuncayBAS

Glad it was resolved with DTLS. Keep in mind.

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5

Tuncay BAS RZK Muhendislik Turkey NSE 4 5 6 FCESP v5
Labels
Top Kudoed Authors