Problema Visualizar DVR

Para temas sobre el uso de las politicas de filtrado en los productos FortiGate.
Responder
mendocino37
Mensajes: 3
Registrado: 21 Mar 2017, 19:07

Problema Visualizar DVR

Mensaje por mendocino37 »

Estimados como estan, tengo problema para visualizar un DVR de mi sucursal ( 10.0.0.5 ip interna fortigate 500D) y 10.1.254.240 ip DVR Hikvision

Tango otro DVR Hikvision con otra IP interna y me anda bien , saliendo por otra IP publica

haciendo un debug con la ip del DVR que no funciona, me salen los RST los cuales hacen que no me muestre las imagenes

6.090416 LACP-to-fwint1 out 10.0.0.5.46661 -> 10.1.254.240.8000: syn 1174788419
6.090418 port15 out 10.0.0.5.46661 -> 10.1.254.240.8000: syn 1174788419
6.091379 port15 in 10.1.254.240.8000 -> 10.0.0.5.46661: syn 298710909 ack 1174788420
6.091380 LACP-to-fwint1 in 10.1.254.240.8000 -> 10.0.0.5.46661: syn 298710909 ack 1174788420
6.108335 LACP-to-fwint1 out 10.0.0.5.46661 -> 10.1.254.240.8000: ack 298710910
6.108336 port15 out 10.0.0.5.46661 -> 10.1.254.240.8000: ack 298710910
6.159432 LACP-to-fwint1 out 10.0.0.5.46661 -> 10.1.254.240.8000: fin 1174788468 ack 298710986
6.159434 port15 out 10.0.0.5.46661 -> 10.1.254.240.8000: fin 1174788468 ack 298710986
6.163359 port15 in 10.1.254.240.8000 -> 10.0.0.5.46661: rst 298710986 ack 1174788469
6.163361 LACP-to-fwint1 in 10.1.254.240.8000 -> 10.0.0.5.46661: rst 298710986 ack 1174788469
6.165572 LACP-to-fwint1 out 10.0.0.5.46661 -> 10.1.254.240.8000: rst 1174788469 ack 298710986


LOG del DVR que funciona

7.408618 LACP-to-fwint1 out 10.0.0.5.49769 -> 10.2.181.182.8100: syn 498556043
7.408620 port15 out 10.0.0.5.49769 -> 10.2.181.182.8100: syn 498556043
7.409823 port15 in 10.2.181.182.8100 -> 10.0.0.5.49769: syn 3060317342 ack 498556044
7.409825 LACP-to-fwint1 in 10.2.181.182.8100 -> 10.0.0.5.49769: syn 3060317342 ack 498556044
7.411298 LACP-to-fwint1 out 10.0.0.5.49769 -> 10.2.181.182.8100: ack 3060317343
7.411299 port15 out 10.0.0.5.49769 -> 10.2.181.182.8100: ack 3060317343
7.444235 LACP-to-fwint1 out 10.0.0.5.49769 -> 10.2.181.182.8100: fin 498556352 ack 3060317527
7.444237 port15 out 10.0.0.5.49769 -> 10.2.181.182.8100: fin 498556352 ack 3060317527
7.445212 port15 in 10.2.181.182.8100 -> 10.0.0.5.49769: fin 3060317527 ack 498556353
7.445214 LACP-to-fwint1 in 10.2.181.182.8100 -> 10.0.0.5.49769: fin 3060317527 ack 498556353
7.523404 LACP-to-fwint1 out 10.0.0.5.49770 -> 10.2.181.182.8100: syn 3770834009
7.523406 port16 out 10.0.0.5.49770 -> 10.2.181.182.8100: syn 3770834009
7.524123 port15 in 10.2.181.182.8100 -> 10.0.0.5.49770: syn 220692142 ack 3770834010
7.524124 LACP-to-fwint1 in 10.2.181.182.8100 -> 10.0.0.5.49770: syn 220692142 ack 3770834010
7.525846 LACP-to-fwint1 out 10.0.0.5.49770 -> 10.2.181.182.8100: ack 220692143
7.525848 port16 out 10.0.0.5.49770 -> 10.2.181.182.8100: ack 220692143
7.542555 LACP-to-fwint1 out 10.0.0.5.49770 -> 10.2.181.182.8100: fin 3770834046 ack 220719855
7.542557 port16 out 10.0.0.5.49770 -> 10.2.181.182.8100: fin 3770834046 ack 220719855
7.543293 port15 in 10.2.181.182.8100 -> 10.0.0.5.49770: fin 220719855 ack 3770834047
7.543294 LACP-to-fwint1 in 10.2.181.182.8100 -> 10.0.0.5.49770: fin 220719855 ack 3770834047
7.616084 LACP-to-fwint1 out 10.0.0.5.49771 -> 10.2.181.182.8100: syn 4137040981
7.616085 port15 out 10.0.0.5.49771 -> 10.2.181.182.8100: syn 4137040981
7.616794 port15 in 10.2.181.182.8100 -> 10.0.0.5.49771: syn 967483351 ack 4137040982
7.616795 LACP-to-fwint1 in 10.2.181.182.8100 -> 10.0.0.5.49771: syn 967483351 ack 4137040982

Les agradecere alguna ayuda
Avatar de Usuario
makco10
Mensajes: 1350
Registrado: 03 Jun 2011, 19:42
Ubicación: Honduras
Contactar:

Re: Problema Visualizar DVR

Mensaje por makco10 »

Hola,

Desde el cli realiza el siguiente comando e intenta confirmar si desde el fortigate llegas al DVR:

execute ping 10.1.254.240

Troubleshooting Tip: Using PING options from the FortiGate's CLI:
[Debes identificarte para poder ver enlaces.]
Defend Your Enterprise Network With Fortigate Next Generation Firewall

NSE4
NSE5
Responder