5.6.2 Policy routing for Fortiguard services
Hi
We use a new FWF60E with 5.6.2 in one of our branches and except the public IP or the HQ Forti (to establish the VPN) we route everything directly into the VPN tunnel to our HQ. That's working fine since years and also now with the new FWF60E, but we can't reach the Fortiguard servers that way, even all the ports to the tunnel are open.
So we would like to create a Policy Route for the FWF60E for all the local traffic going directly to WAN1 and not passing the VPN, but we fail as well. I've read it's not possible to create a Policy Route for local traffic, so therefore my question, how can we solve this problem we have now with 5.6.2 and the Forti can somehow establish the Fortiguard services? Is it true that the Forti needs a direct connection to the WAN for it? Shouldn't it also work through an existing VPN tunnel to connect the Fortiguard services?
Appreciate any suggestion.
Thx
Wayne
