no internet in Fortigate firewall after replaced with ASA firewall

I recently replaced an ASA firewall with Fortigate firewall and I found nobody has internet.
I have created exactly same static routes as in ASA and the static route was a private IP.
Then I added a dynamic pool in the policy with the public IP provided by ISP. Then clients started getting internet.
But when I ping from Fortigate still no internet. Due to that I still cant register the device.
LVL 31
MASEE Solution Guide - Technical Dept HeadAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Jose Gabriel Ortega CastroCEOCommented:
Contact your isp... Maybe the issue is not on the hardware or software point, it should be a configuration in the ISP, remember that they can even match it to a MAC address and of course the MAC of your ASA is different from the one in your FortiGate hardware. give them a call and let you know that you changed your perimeter firewall and get the MAC address (from ASA) handy.
0
MASEE Solution Guide - Technical Dept HeadAuthor Commented:
if I replace the Fortigate with ASA I can ping from ASA.
I checked with ISP. I was told there is no MAC filtering or MAC tagging, This is only point to point.
0
Jose Gabriel Ortega CastroCEOCommented:
Ok, Same static address on ASA and Fortigate?

if so, check the DNS configured in the ASA (and tray a traceroute to 8.8.8.8 for example).
Make sure that you have the DNS server configured and well internet with the lowers priority in the network.
0
Make Network Traffic Fast and Furious with SD-WAN

Software-defined WAN (SD-WAN) is a technology that determines the most effective way to route traffic to and from datacenter sites. Register for the webinar today to learn how your business can benefit from SD-WAN!

buckethead34Commented:
What do your nat statements look like?
0
MASEE Solution Guide - Technical Dept HeadAuthor Commented:
-->Ok, Same static address on ASA and Fortigate?
I have replaced ASA with Fortigate with same IP.
0
myramuCommented:
Hello MAS,

Verify with below tests,
1)Make sure that all interfaces are up and running.
2) Make sure that default route is configured with valid GW.
3) ping  Local IP (execute ping x.x.x.x) from FGT
4) Ping Internet GW (execute ping x.x.x.x) from FGT
5) Ping 8.8.8.8 (execute ping x.x.x.x) from FGT
6) Ping www.google.com (execute ping x.x.x.x) from FGT

Post the above results here.

Good Luck!
0
MASEE Solution Guide - Technical Dept HeadAuthor Commented:
Verify with below tests,
-->1)Make sure that all interfaces are up and running.
Its up and running.
-->2) Make sure that default route is configured with valid GW.
It is configured

-->3) ping  Local IP (execute ping x.x.x.x) from FGT
I can ping local IPs

-->4) Ping Internet GW (execute ping x.x.x.x) from FGT
I can ing Gareway,

-->5) Ping 8.8.8.8 (execute ping x.x.x.x) from FGT
I cannt ping from firewall.

-->6) Pin/.g www.google.com (execute ping x.x.x.x) from FGT
I cannt ping from firewall.
0
myramuCommented:
Hello MAS,

Reduce the MTU value on the wan interface and try. if still same issue, then ISP is doing some blocking.

Good Luck!
0
MASEE Solution Guide - Technical Dept HeadAuthor Commented:
I created a new policy LAN to WAN only for firewall IP,  priority/order changed and it worked.

Thanks to all.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
MASEE Solution Guide - Technical Dept HeadAuthor Commented:
Fixed by adding a policy.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.