Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ozorio
New Contributor

No Internet | Azure FortiGate VM

Hello fellow gurus. I am hoping one of you maybe able to help me with a problem I am facing.

I just deployed two Azure FortiGate VMs using the market place in a HA acive-passive with ELB/ILB.

I am able to get in to the management web interface. When I try to ping 8.8.8.8 from the cli 'exec ping 8.8.8.8' I am getting a 100% loss.

I check and I have the static route setup (which is created by default).

What else am I missing here? I'm new in Azure so it's probably something simple.

Thanks!

192.168.0.1 router login
3 REPLIES 3
mgoswami
Staff
Staff

Hi,

 

May I know if you have used any source for the ping?

 

execute ping-options ?

This will show you if there are any filters set for the source.

If not, may I know if you have enabled VDOM?

 

BR,

Manosh

YBKruthi
Staff
Staff

Hi Ozorio,

 

I understand that you have created the FortiGate VM and tried to reach internet by initiating ping to 8.8.8.8

 

Please check below steps to narrow down the issue:

1. You need to ensure you have default route created towards the Internet facing interface.

2. Check if there is arp entry for the default gateway IP using "get system arp" or "diag ip arp list".

3. Only if arp entry is present, the ping initiated will be forwarded towards Egress interface and you can check on packet capture that the traffic is sent out or not.

 

If it is sent out and there is no ICMP reply packets, then this is not FortiGate concern. 

If there is no ICMP request shown in packet capture, then we can suspect that the issue is with traffic not being sent out of FortiGate VM.

 

Do let me know if you have any other queries/concerns.

 

Thanks,

Kruthi

akushwaha
Staff
Staff

 

Hi,

As I understand you're unable to ping 8.8.8.8 from FortiGate firewall. Please provide me the output of below commands to check further:

 

get router info routing-table details 8.8.8.8

diag sniffer packet any "host 8.8.8.8 and icmp" 4 0 a
<after runnin this command initiate ping traffic >

Best regards,

Abhimanyu

Labels
Top Kudoed Authors