Skip to main content
Christophe_001
New Member
March 5, 2019
Question

Default policy route ipsec tunnel & internet services break-out

  • March 5, 2019
  • 3 replies
  • 5327 views

Hi,

 

I'm searching for a decent solution to implement following:

 

I have 2 fortigates connected true ipsec tunnel and the default traffic goes from branch to HQ true ipsec tunnel. This is done true a policy route and works.

Now, i would like for certain "Internet Services" to take the internet-breakout of the branch firewall, instead of entering the ipsec tunnel to HQ.

 

I have tested this setup, but the "Internet Servcies" that i defined keep on entering the ipsec tunnel.

 

Questions:

Is it possible to change the order of policy routes so that the "static route with internet services" which is in fact a policy route in the background is the first in the list?

 

Is their another way to accomplish this?

 

Thanks in advance

Christophe

 

3 replies

ede_pfau
SuperUser
SuperUser
March 5, 2019

Assuming that with "true" you mean "through"...

 

To determine if policy routing is indeed the right solution I'd like to know how you differentiate the traffic: by destination network, by service (port), by source network,...?

Internet-bound traffic is usually served by a default route, in your setup, pointing to the local breakout at the branch office. Then, either by policy route or regular route, the 'other' traffic is directed towards the tunnel.

Christophe_001
New Member
March 5, 2019

Hi Ede,

 

Yes correct, through :)

 

For the default policy route to work through the IPsec tunnel, i configure the phase 2 selectors with 0.0.0.0 0.0.0.0 & the policy route with destination 0.0.0.0

 

Policy route:

Services is Any

Source is local network

Destination is 0.0.0.0

Gateway is IPSEC Tunnel HQ

Gateway IP is IP on both IPsec interfaces, so the firewall is able to use the policy route

 

Static route:

destination is e.g. Linkedin-Web

exit port is WAN interface (local break-out)

AD is default 10

 

So in this example it's not a spefic network that needs to be routed over the ipsec, but everything destined for internet except certain "Internet Services"

 

Christophe

 

ede_pfau
SuperUser
SuperUser
March 5, 2019

That's what I thought.

If you can decide which route to take just by looking at the destination, then you create a static route.

If you need other selectors, like source network, source port etc., then you create a Policy route.

 

So, for the default internet traffic, just point a default route to the tunnel interface, no gateway.

For specific destinations, try to create static routes with destinations from the "Internet services" DB. This depends on the FortiOS version.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!