Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
heskez
New Contributor III

FG200A I Don't see traffic flowing when doing a diag sniffer packet on interface wan1

Hi there, 

 

When i execute a "diag sniffer packet wan1" I don't see any traffic. 

wan1 is in a separate Vdom. 

Communication is working and the firewall rule has log option activated. 

The FW is an oldie FG200A. What's wrong here?

 

Best r,

E

 

6 REPLIES 6
emnoc
Esteemed Contributor III

The cli command diag debug flow with the filters applied would be your starting point. Maybe the traffic is drop before hitting wan1 ( uRPF, deny-action,etc...)

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
heskez
New Contributor III

Thanks, Executed without filters I do see some "general traffic" something what I wouldn't expect within this Vdom. But I don't see the traffic I'd like to see. 

 

emnoc
Esteemed Contributor III

Than your host is not hitting the firewall. You can bypass the firewall if your traffic is allowed or deny would result in a match in  trace.

 

I would do it again & with filters  for either src dst address or port and re-evaluate.

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
heskez
New Contributor III

Thanks Ken, I've tried your suggestion. However, even with filters I'm not able to discover the hosts I'm looking for neither the traffic. I've also looked into the Fortianalyzer and shows me the same results. So no traffic and no hosts I'm looking for. A Thing I forgot to mention, I'm looking for VOICE traffic.

 

"I was able to see the VOICE traffic before"

 

Best,

E

emnoc
Esteemed Contributor III

1>

The diag sniffer packet,  shows  no traffic

 

2>

The diag debug flow, shows no traffic

 

 

That means that traffic is NOT going thru your fortigate.What does a trace route show between the 2 hosts involved?

 

Are the two hosts involved on  the same local subnet ?

 

Ken

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
heskez
New Contributor III

Hi Ken, 

 

1> and 2> yes and yes. Although I agree with your opinion traffic is not hitting the firewall in theory, I'm confused.

Why? People are calling :) The ip softphones are physically connected via a switch to the firewall. Scary isn't it?

 

Best,

E

 

Labels
Top Kudoed Authors