Skip to main content
seshuganesh
Staff
Staff
March 30, 2022

Technical Tip: Policy routes will not work for FortiGate initiated traffic

  • March 30, 2022
  • 0 replies
  • 4337 views
Description

This article describes that policy routes will not work for FortiGate-initiated traffic.

Scope FortiGate.
Solution

Policy routes are designed for forwarding traffic not for local out traffic.

 

Let's say that a specific subnet has been configured to forward through specific gateway using policy route, and to test the policy route by initiating the traffic from the firewall, it will not work.

Results will be unexpected.

 

Even if a source is mentioned as the LAN interface IP of the firewall while pinging using this command:

 

execute ping-options source 192.168.0.1 <----- If 192.168.0.1 is the lan interface IP.

 

It will not match the policy route, because still it is local out traffic only.

 

To test policy routes working, use the internal machine and initiate traffic.

 

Because these policy routes are designed for forwarding traffic.

 

Related articles:

Technical Tip: Pinging out to Internet from local interface

Technical Tip: Unable to ping public servers (for testing) using ping-option source interface

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!