cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

One way routing

887
Views
0
Helpful
1
Comments
Beginner

Hi everyone

 

I've attached a basic diagram which hopefully explains my setup. Please see Diagram 1a. This time, I've also added routes that I currently have configured on each device.

 

Routes on Vodafone router:

10.0.136.0               255.255.255.0          10.0.135.1

 

Routes on the Core switch:

10.0.136.0              255.255.255.0          10.0.135.6

10.136.0.0               255.255.0.0          10.0.135.6

 

Routes on Checkpoint:

213.156.18.102        192.168.19.11          255.255.255.255      UGHD 0 0 0 External

192.168.19.0            0.0.0.0                   255.255.255.0          U 0 0 0 External

10.0.135.0               0.0.0.0                    255.255.255.0         U 0 0 0 Internal

89.138.200.0            192.168.19.11          255.255.248.0         UGD 0 0 0 External

10.135.0.0               10.0.135.1               255.255.0.0             UGD 0 0 0 Internal

10.0.0.0                  10.0.135.250            255.0.0.0                UGD 0 0 0 Internal

0.0.0.0                   192.168.19.11          0.0.0.0                    UGD 0 0 0 External

 

The problem:

Users on 10.90.0.0 /16 are unable to access the 10.136.0.0 /16 network. Diagram 1b shows a traceroute from 10.90.0.0/16 to 10.136.128.1. It times out after hitting 10.0.135.1

 

Access the other way works fine. Users on 10.136.0.0 /16 can access 10.90.0.0 /16 fine but the traceroute looks odd to me. It can be seen in Diagram 1c.

 

Would you be able to review the routes I currently have in place and confirm where I'm going wrong please? I'd like to clarify that the routes I currently have in place are correct. Also, would like assistance on what route I need to add on the Fortigate.

 

Many thanks in advance.

1 Comment
Beginner

Hello,

I think that the following route is missing on the Checkpoint firewall:

  • 10.90.0.0/16 via 10.0.135.1

Without this route, trafic coming from Site B has to pass through Vodafone Router to reach 10.90.0.0/16 but Vodafone router does not have a specific route to this subnet.