Technical Tip: Management traffic is not matching to specific interface even when route is available
| Description | This article describes how management traffic flows when there are multiple routes active along with multiple interfaces for the destination. |
| Scope | FortiGate. |
| Solution |
Example: 192.168.1.0/24 network route is available for multiple tunnels i.e. spoke 1, spoke 2, and spoke 3. There is FortiManager IP(192.168.1.4), where the requirement is that FortiManager traffic should be routed to the spoke 3 tunnel.
An alternative approach, beyond configuring the tunnel interface IP address, available in FortiOS 7.4.0 and later, involves setting the preferred source (see Technical Tip: Configuring preferred-source in source IP for local-out traffic) in static routes or SD-WAN members. The newly specified preferred-source address will be applied to all local-out management traffic routed through that path. To check the debug flow, follow the instructions in Technical Tip: Debug flow tool. To identify active and inactive routes in the firewall, follow the instructions in Technical Tip: How to identify inactive routes in the Routing Table. |