Hot!Cannot ping to fortigate vlan interface

Author
oes
New Member
  • Total Posts : 4
  • Scores: 0
  • Reward points: 0
  • Joined: 2020/10/24 05:56:36
  • Status: offline
2020/10/24 06:06:03 (permalink)
0

Cannot ping to fortigate vlan interface

I created VLAN with IP 10.0.1.1/255.255.255.0 for lan. In the firewall policy, I created a rule that allows access from the lan to the VLAN.
When connecting with a laptop to lan, ping 10.0.1.1 is not available.
FG-100E, FortiOS v6.4.1 build1637.
How to fix?
#1

9 Replies Related Threads

    boneyard
    Gold Member
    • Total Posts : 364
    • Scores: 16
    • Reward points: 0
    • Joined: 2014/07/30 11:15:18
    • Status: offline
    Re: Cannot ping to fortigate vlan interface 2020/10/25 01:28:27 (permalink)
    0
    did you allow ping on the VLAN interface?
     
    https://docs.fortinet.com...e-access-to-interfaces
     
    do you use trusted hosts on the admin accounts? if yes, is the LAN subnet there?
    #2
    simonorch
    Gold Member
    • Total Posts : 342
    • Scores: 14
    • Reward points: 0
    • Joined: 2009/06/05 00:05:08
    • Location: Norway
    • Status: offline
    Re: Cannot ping to fortigate vlan interface 2020/10/25 23:46:56 (permalink)
    0
    I would also highly recommend you patch to 6.4.2 or 6.4.3, likely not related to this specific problem, but you will hopefully avoid others

    NSE8
    Fortinet Expert partner - Norway
    #3
    oes
    New Member
    • Total Posts : 4
    • Scores: 0
    • Reward points: 0
    • Joined: 2020/10/24 05:56:36
    • Status: offline
    Re: Cannot ping to fortigate vlan interface 2020/10/26 01:19:26 (permalink)
    0
    Updated to FortiOS v6.4.3 build1778.
    Ping is allowed everywhere.
    "trusted hosts on the admin accounts" - where are they located in the GUI? Or customize only in the CLI?
    #4
    boneyard
    Gold Member
    • Total Posts : 364
    • Scores: 16
    • Reward points: 0
    • Joined: 2014/07/30 11:15:18
    • Status: offline
    Re: Cannot ping to fortigate vlan interface 2020/10/26 11:50:29 (permalink)
    0
    possible via GUI, just look if trusted hosts are enabled on the admin accounts.
     
    if not that is not your issue.
     
    diagnose sniffer packet any 'host 10.0.1.1'
     
    and then performing the ping from the workstation would be an interesting next step
     
    post edited by boneyard - 2020/10/28 10:58:10
    #5
    simonorch
    Gold Member
    • Total Posts : 342
    • Scores: 14
    • Reward points: 0
    • Joined: 2009/06/05 00:05:08
    • Location: Norway
    • Status: offline
    Re: Cannot ping to fortigate vlan interface 2020/10/27 00:36:40 (permalink)
    0
    A couple of more thoughts for you.
     
    I take it you don't have vdoms enabled and the two interfaces are in different vdoms?
    How about source nat on the relevant firewall rule? 
     
    Also worth seeing how the firewall is handling those packets 
     
    diag debug flow filter addr 10.0.1.1
    diag debug flow trace start 50
    diag debug en

    NSE8
    Fortinet Expert partner - Norway
    #6
    oes
    New Member
    • Total Posts : 4
    • Scores: 0
    • Reward points: 0
    • Joined: 2020/10/24 05:56:36
    • Status: offline
    Re: Cannot ping to fortigate vlan interface 2020/10/27 06:07:01 (permalink)
    0
    Trusted hosts in administrator accounts are not enabled.
    "diagnose sniffer packets any 'host 10.0.1.1'" - command result "Command fail. Return code -61".
     
    vdoms not included.
    post edited by oes - 2020/10/27 06:11:49
    #7
    simonorch
    Gold Member
    • Total Posts : 342
    • Scores: 14
    • Reward points: 0
    • Joined: 2009/06/05 00:05:08
    • Location: Norway
    • Status: offline
    Re: Cannot ping to fortigate vlan interface 2020/10/27 06:44:49 (permalink)
    0
    he made a little typo it's packet not packets
     
    try
    diagnose sniffer packet any 'host 10.0.1.1'

    NSE8
    Fortinet Expert partner - Norway
    #8
    oes
    New Member
    • Total Posts : 4
    • Scores: 0
    • Reward points: 0
    • Joined: 2020/10/24 05:56:36
    • Status: offline
    Re: Cannot ping to fortigate vlan interface 2020/10/28 02:00:02 (permalink)
    0
    Execution result:
    "interfaces=[any]
    filters=[host 10.0.1.1]
    0 packets received by filter
    0 packets dropped by kernel"
    #9
    boneyard
    Gold Member
    • Total Posts : 364
    • Scores: 16
    • Reward points: 0
    • Joined: 2014/07/30 11:15:18
    • Status: offline
    Re: Cannot ping to fortigate vlan interface 2020/10/28 11:01:08 (permalink)
    0
    assuming you performed a ping it seems the firewall doesn't see it.
     
    can you share the interface config and firewall policy, screenshots might help else CLI output.
    #10
    Jump to:
    © 2020 APG vNext Commercial Version 5.5