Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jeff_the_Network_Guy
New Contributor III

Fortigate doesn't know its on the Internet?

I'm setting up my first HA enabled 301E's running FortiOS 5.6.5 to replace our solo 300C that is stuck on FortiOS 5.2.  Since I cannot just drop it in and go, I'm trying to build the replacement units off to the side, but I'm kind of stuck.  I the 301E's on a circuit we were not using, so I can try to get it to phone home, register, check license, etc... I can plug a laptop into the circuit, set a static address, and get out onto the internet, but when I plug the circuit into the into the firewall it knows it is connected, but does not seem to have Internet access.  I put a dumb switch in between the the AdTran from the provider and Fortigate so I could plug my laptop in and ping the exterior interface of the firewall as a test.  There aren't any errors, and the port in question is setup a WAN.  I can ping the gateway address from the CLI, but I cannot ping or trace past it from the firewall.  I do have a "zero route" on the interface pointing to the gateway address.  Is there something else I am missing here?  

----------------(-- Jeff
----------------(-- Jeff
2 Solutions
lobstercreed
Valued Contributor

Are there any other "zero", or default, routes configured that might be more preferred?  Perhaps a route you set so that you could talk to it internally? 

 

You should be able to check Monitor > Routing Monitor to see what routes are actually installed.

View solution in original post

Toshi_Esumi
SuperUser
SuperUser

I would suspect the provider side. You can confirm it if you set the same IP to your laptop connected to the switch, and disconnect the 301E from the switch, then try to get to any IPs on the internet.

View solution in original post

3 REPLIES 3
lobstercreed
Valued Contributor

Are there any other "zero", or default, routes configured that might be more preferred?  Perhaps a route you set so that you could talk to it internally? 

 

You should be able to check Monitor > Routing Monitor to see what routes are actually installed.

Toshi_Esumi
SuperUser
SuperUser

I would suspect the provider side. You can confirm it if you set the same IP to your laptop connected to the switch, and disconnect the 301E from the switch, then try to get to any IPs on the internet.

Jeff_the_Network_Guy

LobsterCreed is the winner on this episode of "what did I misconfigure".  I had a zero route from the intial config where the only valid interface was MGMT.  

----------------(-- Jeff
----------------(-- Jeff
Labels
Top Kudoed Authors