Technical Tip: Response traffic of a Virtual IP Session Egresses through a Different Interface than the Original Incoming interface
| Description | This article describes an issue where the reply traffic for Virtual IP (VIP) egresses from a different interface when a security profile(UTM) is enabled in the VIP firewall policy that uses proxy-based inspection mode. |
| Scope | FortiGate v7.4.2, v7.4.3. |
| Solution | After upgrading FortiGate to v7.4.2, and v7.4.3, Virtual IPs do not work when UTM is enabled in the firewall policy with proxy-based Inspection mode. The problem can be verified by examining the logs as outlined below. Packet sniffers will show that the FortiGate responds to the client-initiated traffic, but it is routed via a different interface than the original incoming interface. Thus, the reply traffic does not arrive on the client machine. Sniffer output from non-working scenario:
Sniffer output from the working scenario when UTM is disabled in the firewall policy or when the firewall policy is in flow-based Inspection mode:
This issue has been resolved in v7.4.4 Workaround:
OR.
|
