Skip to main content
skaneria
Staff
Staff
October 28, 2020

Technical Tip: Debug shows 'pre_route_auth check fail(id=0), drop' over SSL VPN while accessing VIP

  • October 28, 2020
  • 0 replies
  • 5424 views
Description
This article describes the message 'pre_route_auth check fail(id=0), drop' while accessing the VIP over SSL VPN debug.

Solution
It is not possible to access the VIP over the SSL VPN.
This happens when multiple ISP and VIP are configured to access the resources.

For example, VIP is configured on 'Port2'.




Firewall has 2 ISP configured on 'Port1' and 'Port2', however SSL VPN policy is from ssl.root to 'Port1' as below.





If user try to access the resource over port 4433, it will not be accessible and debug will show 'pre_route_auth check fail(id=0), drop' error.

Resolve this by changing the outgoing interface to 'Port2' in the SSL VPN policy.





Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!