Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Bug] Fortigate and tcpreplay #852

Open
scdit46 opened this issue Apr 21, 2024 · 2 comments
Open

[Bug] Fortigate and tcpreplay #852

scdit46 opened this issue Apr 21, 2024 · 2 comments

Comments

@scdit46
Copy link

scdit46 commented Apr 21, 2024

From a laptop I am injecting six ICMP packets (three request packets and three response packets) to reach an interface of a Fortigate firewall (port 9).

The problem is that for some unknown reason the request packets do not reach the Fortigate interface (the command diagnose sniffer packet port9 does not display the packets),

If it injects the traffic to another laptop, I do receive both the requests and the replies. This behavior occurs with other protocols (UDP, TCP), outbound traffic does not arrive.

I have opened a case with Fortigate and the blame is placed on tcpreplay.

The fact is that I tried with a TAP to see if it was putting the packets on the cable and it was verified. That could be happening?

fg1

If I send the packets of SPAN switch to port9 of Fortigate I see all packets (request and reply) .

What is happenning?

@scdit46
Copy link
Author

scdit46 commented Apr 21, 2024

For check that I send 3 request + 3 reply to wire I connect one TAP device.

In laptop with wireshark I see 3 request and 3 reply but In Fortigate I see only 3 replys.
The statistics of interface port9 of Fortigate only counts the reply paquetes.

The support Fortigate blames the use I give to the tcpreplay tool.

I don't know what I'm doing wrong, I see the packets in Wireshark of the computer connected to the TAP port monitor.

what could be happening?

fg2

@scdit46
Copy link
Author

scdit46 commented Apr 21, 2024

In this case, I have a little network (ALFA and BETA laptops connected to TAP). The Port Monitor of TAP send the traffic between ALFA and BETA. ALFA send 3 request of ping to BETA and BETA send 3 reply, then the Port Monitor of TAP send 6 paquetes and in port9 of Fortigate I see 6 packets..

What is happening?

I am lost!!
fg3

@scdit46 scdit46 changed the title [Bug] Fortigate and tcplreplay [Bug] Fortigate and tcpreplay Apr 21, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants