Skip to content

Section 6: Testing the deployment

Step 6.1: Ingress test

Using the floating public IP assigned to the FortiGate-A untrust port, try to reach the spoke VMs using the specific ports configured earlier:

text
TCP/2244
TCP/2245

SSH to Spoke1-VM:

SSH to Spoke1 VM

SSH to Spoke2-VM:

SSH to Spoke2 VM

Verification:

Verify Spoke1 VM SSH Access

Verify Spoke2 VM SSH Access

Check the FortiGate traffic logs.

Navigation path:

text
Log & Report > Forward Traffic

FortiGate Ingress Traffic Logs


Step 6.2: Egress test

Try to ping Google DNS 8.8.8.8 from Spoke1-VM or Spoke2-VM.

Ping Google DNS from Spoke VM

You can also use the curl command to reach www.fortinet.com.

Test Internet Access with Curl

Check the FortiGate traffic logs.

Navigation path:

text
Log & Report > Forward Traffic

FortiGate Egress Traffic Logs


Step 6.3: East/West test

Try to reach Spoke2-VM from Spoke1-VM using SSH or Telnet to TCP port 22, as shown below.

Test East-West Traffic Between Spoke VMs

Check the FortiGate traffic logs.

Navigation path:

text
Log & Report > Forward Traffic

FortiGate East-West Traffic Logs


Checkpoint

Before continuing, confirm that:

  • SSH access to Spoke1-VM works through TCP port 2244.
  • SSH access to Spoke2-VM works through TCP port 2245.
  • Ingress traffic appears in the FortiGate forward traffic logs.
  • Spoke1-VM or Spoke2-VM can reach 8.8.8.8.
  • The curl test to www.fortinet.com succeeds.
  • Egress traffic appears in the FortiGate forward traffic logs.
  • Spoke1-VM can reach Spoke2-VM using TCP port 22.
  • East-West traffic appears in the FortiGate forward traffic logs.

FortiGate OCI Hands-on Lab Guide