Default policy route ipsec tunnel & internet services break-out
Hi,
I'm searching for a decent solution to implement following:
I have 2 fortigates connected true ipsec tunnel and the default traffic goes from branch to HQ true ipsec tunnel. This is done true a policy route and works.
Now, i would like for certain "Internet Services" to take the internet-breakout of the branch firewall, instead of entering the ipsec tunnel to HQ.
I have tested this setup, but the "Internet Servcies" that i defined keep on entering the ipsec tunnel.
Questions:
Is it possible to change the order of policy routes so that the "static route with internet services" which is in fact a policy route in the background is the first in the list?
Is their another way to accomplish this?
Thanks in advance
Christophe
