Skip to main content
ganesh_karale
Explorer III
July 2, 2024
Question

Default route in case of Zscaler proxy

  • July 2, 2024
  • 6 replies
  • 2944 views

Hi, Users are using zscaler proxy for internet.

We are having zscaler s2s vpn tunnels configured and added default route for internet.

 

Zscaler tunnel - distance - 10, priority - 1

Internet ILL - distance - 10, priority - 2

 

Now if we do the ping to ILL wan ip we are not getting ping of wan ip.

If we do priority 1 to ILL and priority 2 to Zscaler tunnel then only we are able to ping to wan ip.

Can someone please guide in this case.

6 replies

fricci_FTNT
Staff
Staff
July 2, 2024

Hi @ganesh_karale ,

 

It sounds an asymmetric routing issue to me, please check if the routing is working as expected in your infrastructure.
Please attach a diagram that shows the devices involved and their IP, also shows from where your users are pinging.
Running a packet capture on both ends would be good to understand if and where the packet are received:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Using-the-FortiOS-built-in-packet-sniffer/ta-p/194222

On the FortiGate you can also run a debug flow at the same time of the packet sniffer (on a second SSH window, to avoid mixing up the logs):
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-First-steps-to-troubleshoot-connectivity/ta-p/192560

Best regards,

ganesh_karale
Explorer III
July 2, 2024

When we do packet capture it shows that if we are pinging to wan ip from public network traffic receiving on wan interface but reply going out via zscaler.

fricci_FTNT
Staff
Staff
July 2, 2024

Hi @ganesh_karale ,

 

If you attach a diagram which shows the IPs and the devices involved, it would be beneficial.
You might find the below article useful:
https://community.fortinet.com/t5/FortiGate/Technical-Note-Routing-behavior-depending-on-distance-and/ta-p/198221

You can also collect the following (x.x.x. are the three first octets and x.x.x.x is the IP you are pinging):

get router info routing-table all | grep x.x.x.
get router info routing-table database | grep x.x.x.
get router info routing-table detail x.x.x.x/32

diag ip rtcache list | grep x.x.x.
get router info kernel | grep x.x.x.


Best regards,

hbac
Staff
Staff
July 2, 2024

Hi @ganesh_karale,

 

You can use policy route to route traffic over the tunnel. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-the-firewall-Policy-Routes/ta-p/189996

 

Regards, 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!