Dynamic Routing on a FG 3960E
- November 5, 2019
- 2 replies
- 2794 views
Hello, I'm new here and have a problem (of course ;) ) We're working on a new setup that is using 2 3960E (FortiOS 6.0.6) in an ACTIVE/STANDBY HA. I've attached a very rudimentary design that hopefully helps to understand what I'm trying to describe. The FWs are connected via OSPF to 2 multilayer switches via 2 transfer VLANs. The clients in this setup use the Firewall as a Gateway und the multilayer switches are gateways (HSRP) for the servers. The whole setup is a 100% symmetric which means that both transfer VLANs are in the routing table of the firewall with the same metric and distance. With ECMP active we have some weird effects regarding dynamic routing: When a client tries to reach a server, i.e. ping, the connection can take either VLAN towards the server and come back over the other VLAN. This behaviour itself is not unusual and actually desired but the Fortigate behaves weird when this happens. First of all the fortigate does not produce a log entry for this connection only for the ones where both packets take the same way. Secondly there is no NPU offloading for this session. Mind you the ping still works but the behaviour is still bothersome. For other connection types (i.e. HTTPS) we sometimes witness unsuccessful connections when dynamic routing is active, whenever we deactivate one of the transfer VLANs everything works a ok again but this can't be the solution. I hope I was able to describe our issues and hope somebody has an idea of how we can tackle this beast. Thank you so much
Kind regards
Searchingforanswers
