Exercise 3 - Egress
Egress traffic to the Internet from the Spoke VPCs
Success Requirement
- From Workload A - ping/curl/wget public services.
ping 8.8.8.8orping 1.1.1.1curl ipinfo.iowhat IP do you see? You can also usessh sshmyip.comss -naton Workload A and confirm the source is the original source IP.
Tip
FortiGate offers powerful diagnostic tools. Try some of the following when connecting
diag sniffer packet any ‘icmp’ 4 0 1
diag sniffer packet any ‘tcp and port 443’ 4 0 1
diag sniffer packet any ‘host 1.1.1.1’ 4 0 1 - if you want to focus on a specific destination for a ping for example
Help I'm Lost!
- Create a Policy? From where to where?
