Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
yihad92
New Contributor

Traffic blocked by implicit Deny FortiGate 80D

I am trying to connect through a vpn using Zywall to a Public IP address.

 

I added the Public IP to the policy but still getting no access through a vpn. I checked the log and the traffic is going forward and blocked by the implicity polcy.

 

Any idea what will be the issue?

 

Regards,

6 REPLIES 6
Toshi_Esumi
SuperUser
SuperUser

Probably the tunnel is not up and/or routes into the tunnel don't exist.

makco10

In this case you can do a diag flow to check the traffic behavior:

 

http://kb.fortinet.com/kb/documentLink.do?externalID=FD33882

 

http://makcotechgeek.com/fortigate-debug-flow-tool/

 

Regards.

Defend Your Enterprise Network With Fortigate Next Generation Firewall
Defend Your Enterprise Network With Fortigate Next Generation Firewall
yihad92

Any other idea what it could be? I am getting errors using the CLI.

makco10

You can use putty and connect via telnet/ssh:

 

https://www.putty.org/

 

Regards.

Defend Your Enterprise Network With Fortigate Next Generation Firewall
Defend Your Enterprise Network With Fortigate Next Generation Firewall
yihad92

Getting Unknow action 0.

 

What it could be this error?

makco10

Are you using vdom?

 

In this case you have to do this:

 

config vdom
edit root

 

Regards.

Defend Your Enterprise Network With Fortigate Next Generation Firewall
Defend Your Enterprise Network With Fortigate Next Generation Firewall
Labels
Top Kudoed Authors