• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 64
  • Last Modified:

no internet in Fortigate firewall after replaced with ASA firewall

I recently replaced an ASA firewall with Fortigate firewall and I found nobody has internet.
I have created exactly same static routes as in ASA and the static route was a private IP.
Then I added a dynamic pool in the policy with the public IP provided by ISP. Then clients started getting internet.
But when I ping from Fortigate still no internet. Due to that I still cant register the device.
0
MAS (MVE)
Asked:
MAS (MVE)
  • 5
  • 2
  • 2
  • +1
1 Solution
 
Jose Gabriel Ortega CEE Solution Guide - CEO Faru Bonon ITCommented:
Contact your isp... Maybe the issue is not on the hardware or software point, it should be a configuration in the ISP, remember that they can even match it to a MAC address and of course the MAC of your ASA is different from the one in your FortiGate hardware. give them a call and let you know that you changed your perimeter firewall and get the MAC address (from ASA) handy.
0
 
MAS (MVE)EE Solution GuideAuthor Commented:
if I replace the Fortigate with ASA I can ping from ASA.
I checked with ISP. I was told there is no MAC filtering or MAC tagging, This is only point to point.
0
 
Jose Gabriel Ortega CEE Solution Guide - CEO Faru Bonon ITCommented:
Ok, Same static address on ASA and Fortigate?

if so, check the DNS configured in the ASA (and tray a traceroute to 8.8.8.8 for example).
Make sure that you have the DNS server configured and well internet with the lowers priority in the network.
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

 
buckethead34Commented:
What do your nat statements look like?
0
 
MAS (MVE)EE Solution GuideAuthor Commented:
-->Ok, Same static address on ASA and Fortigate?
I have replaced ASA with Fortigate with same IP.
0
 
myramuCommented:
Hello MAS,

Verify with below tests,
1)Make sure that all interfaces are up and running.
2) Make sure that default route is configured with valid GW.
3) ping  Local IP (execute ping x.x.x.x) from FGT
4) Ping Internet GW (execute ping x.x.x.x) from FGT
5) Ping 8.8.8.8 (execute ping x.x.x.x) from FGT
6) Ping www.google.com (execute ping x.x.x.x) from FGT

Post the above results here.

Good Luck!
0
 
MAS (MVE)EE Solution GuideAuthor Commented:
Verify with below tests,
-->1)Make sure that all interfaces are up and running.
Its up and running.
-->2) Make sure that default route is configured with valid GW.
It is configured

-->3) ping  Local IP (execute ping x.x.x.x) from FGT
I can ping local IPs

-->4) Ping Internet GW (execute ping x.x.x.x) from FGT
I can ing Gareway,

-->5) Ping 8.8.8.8 (execute ping x.x.x.x) from FGT
I cannt ping from firewall.

-->6) Pin/.g www.google.com (execute ping x.x.x.x) from FGT
I cannt ping from firewall.
0
 
myramuCommented:
Hello MAS,

Reduce the MTU value on the wan interface and try. if still same issue, then ISP is doing some blocking.

Good Luck!
0
 
MAS (MVE)EE Solution GuideAuthor Commented:
I created a new policy LAN to WAN only for firewall IP,  priority/order changed and it worked.

Thanks to all.
0
 
MAS (MVE)EE Solution GuideAuthor Commented:
Fixed by adding a policy.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

  • 5
  • 2
  • 2
  • +1
Tackle projects and never again get stuck behind a technical roadblock.
Join Now