02-13-2024 11:56 PM
Hi everyone,
Can some one tell me or point me in the right direction on how to configure and verify if ICMP type 3 & 11 are allowed in a fortigate firewall, to make sure ThousandEyes are showing the correct path visualization?
I want to make sure that the documentation shown here are followed:
Protocol
|
ICMP Types
|
IPv4
|
3, 11
|
IPv6
|
1-4, 129
|
Solved! Go to Solution.
02-20-2024 11:26 PM
We changed one of the tests to run path trace mode: in-session and the user-agent to something other than the default.
That solved some of the issues.
The funny thing about this was that an traceroute using TCP-SYN port 443 was shown correctly when done on the CLI but when the TE agent did the default it failed. We have not figured out why.
But the workaround is showing us some more data.
02-15-2024 08:01 AM - edited 02-15-2024 08:07 AM
Hi, Rasmus!
https://community.fortinet.com
https://support.fortinet.com
Configuration will vary, depending on how your network is designed and which actual Fortigate product/version you're using. The latest Fortigate FortiOS documentation on firewall policies can be found here:
https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/118003/policies
And, a quick search in the community turned up the following guidance:
https://community.fortinet.com/t5/Support-Forum/Default-allow-ICMP/m-p/63968
Kindly,
Jeremy Stark
Technical Consulting Engineer
ThousandEyes (part of Cisco)
02-20-2024 11:26 PM
We changed one of the tests to run path trace mode: in-session and the user-agent to something other than the default.
That solved some of the issues.
The funny thing about this was that an traceroute using TCP-SYN port 443 was shown correctly when done on the CLI but when the TE agent did the default it failed. We have not figured out why.
But the workaround is showing us some more data.
02-22-2024 03:31 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide