Skip to main content
PauloP
New Member
June 7, 2010
Solved

Admin Distance for VPN automatic Routes

  • June 7, 2010
  • 2 replies
  • 7515 views
Hi, I set up a VPN hub/spoke structure with a Dialup server and some Remote branches (all appliances are Fortigate 60B). Surprisingly, I observed an Automatic Static Route that appeared on the Dialup server pointing to Remote network, with an Administrative Distance =1. I did not see this feature in the documentation. On the remote site I could not see any automatic route (I put a manual one). My question is: how to change this AD to a suitable value? The VPN function is to serve as backup and I need to set an AD greater than normal route. Regards,
    Best answer by PauloP
    I found out how to set AD. In ipsec phase1-interface, using CLI, there is a parameter " distance" that controls the value of AD. It works. The problem is solved.

    2 replies

    PauloP
    PauloPAuthorAnswer
    New Member
    June 9, 2010
    I found out how to set AD. In ipsec phase1-interface, using CLI, there is a parameter " distance" that controls the value of AD. It works. The problem is solved.
    Creepstian
    New Member
    January 11, 2017

    This article solved my problem, I just wanto to add; to see all the configuration you need to use

    show full-configuration

    because all the default configuration wont be display.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!