FGT60D Policy Routes always denied
Hoping somebody can help me get Policy Routes working on an old FGT60D v5.2.0. I realise it's an old firmware but not able to upgrade for the moment!
The FGT60D has an ISP WAN interface, a LAN interface for my regular home network, and a DMZ interface on 192.168.0.1/24, which is my home lab network. My home lab has a Palo Alto VM on 192.168.0.254, which is the outside "untrusted" interface for my lab.
I want internet SMTP traffic to be routed out the DMZ port without address translation to my home lab. There's no blocking of SMTP by my ISP; I'm currently using destination NAT on the FGT60D to a postfix VM in my home lab, which works fine, except that the source of all mails are shown as 192.168.0.1. And that's what I want to try to solve with policy routing. My understanding is that the onbound SMTP will hit the Palo Alto with the original source address.
No matter what I've tried, I can't get it working, and can only see connection attempts as "deny" in the Local Traffic logs:
Deny log: deny — ImgBB (ibb.co)
Policy Route: policy-route — ImgBB (ibb.co)
IPV4 Policy: ipv4-policy — ImgBB (ibb.co)
Hopefully I'm even in the right ballpark using policy routing in the first place to try and preserve source IP. Any help would be really appreciated.
