BUG in Mature Firmware? - msg="iprope_in_check() check failed on policy 0, drop"
Hello,
I havent seen such weird behavior on FGT before. I have S2S VPN with another location where there is some Local network - all is working good with s2s, but the problem is with local asset. After sometime one of IP is unreachable.
Debug commands says:
.."
id=20085 trace_id=161 func=init_ip_session_common line=6043 msg="allocate a new session-00bf3a66, tun_id=0.0.0.0"
id=20085 trace_id=161 func=vf_ip_route_input_common line=2611 msg="find a route: flag=80000000 gw-10.0.201.2 via root"
.."
id=20085 trace_id=161 func=fw_local_in_handler line=500 msg="iprope_in_check() check failed on policy 0, drop"
I do have enabled "snat-route-change enable" - for SDWan
I dont know why there is some problem with routing, where all is done as I used to do it regarding IPsec. Ive notice it after upgrade to 7.0.13(Mature)
Ive got a temporary workaround, I must flush iprobe routing with "diagnose firewall iprope flush".
Can someone point out what the hack? :)

