Skip to main content
FortiKoala
Staff
Staff
September 28, 2018

Technical Note: Configure Routes for Sub-Interfaces

  • September 28, 2018
  • 0 replies
  • 1039 views
Description
Configure Routes for Sub-Interfaces

Solution
Issue:  SSL Agent communication failing due to traffic being received and transmitted out different interfaces on Network Sentry.  In order for SSL agent communication to be successful, the communication must come in and out the same interface. 

Agent traffic is handled using eth1 (if a pair, this interface is on the Application Server). 

Example: Agent traffic resolves to interface eth1:3.  Without a static route, traffic sent to the IP Address of eth1:3 sub-interface is responded to out the physical eth1 interface. 

Solution:  Add a static route to the eth1 sub-interface the agent communication resolves to.  In this example, by adding a static route to the eth1:3 sub-interface, responses are sent back out the eth1:3 sub-interface.

Here is an example of setting a static route to a sub-interface:
any net 160.87.218.0/23 gw 160.87.89.161 dev eth1:3





Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!