FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jintrah_FTNT
Staff
Staff
Article Id 191079
Article

Description

The FortiGate does not answer ping requests.

Components

  • All FortiGates.
  • All FortiOS versions including 5.6.x and below versions.

Steps or Commands

Issue:

PING is enabled as Administrative Access on the interface, yet the interface does not reply to Ping requests.

Cause:

Trusted hosts are defined for Admin accounts.

Solution:

Trusted hosts also apply to ICMP echo requests.

To have the FortiGate responding to ping requests whatever the originator, add an additional restrictive Admin account with no trusted hosts associated with it. For example, default 0.0.0.0/0.0.0.0. Give the new Admin account a complex name, set it with an Access Profile that has no privileges, and use a complex password.

Note: From version 6.0.x onwards, ping service on management interfaces are not included within the scope of trusted hosts. This means that you will be able to ping the interface from an IP that is not included within trusted hosts.


Contributors