Fortigate is not sending icmp redirects.
Fortigate is not sending icmp redirects.
"icmp-send-redirect" is setting enable.
I would like to be able to send ICMP redirects using the case 2 pattern.
If the PC is in the same segment as the FW,ICMP redirect responses are possible.
However, if there is a router between the PC and the FW and they are on different segments,
ICMP redirect responses will not be received.
Q
Aren't ICMP redirects sent to another segment?How does it work?
Case 1
In this case, the FW sent an ICMP redirect.
PCâ‘ ------[FWâ‘ ]------PCâ‘¡
   |
   ----[FW②]------PC③
setting
PC①:192.168.1.1/24
PC②:192.168.2.1/24
PC③:192.168.3.1/24
routing
PCâ‘ : Default gateway is FWâ‘
FWâ‘ : Setting static route "Gateway of destination PCâ‘¢ is FWâ‘¡"
Case 2
PCâ‘ ----[RTâ‘ ]------[FWâ‘ ]------PCâ‘¡
        |
        ----[FW②]------PC③
setting
PC①:192.168.1.1/24
PC②:192.168.2.1/24
PC③:192.168.3.1/24
RT①:Do not use NAT
routing
PCâ‘ : Default gateway is RTâ‘
FWâ‘ : Setting static route "Gateway of destination PCâ‘¢ is FWâ‘¡"
FWâ‘¡: Setting static route "Gateway of destination PCâ‘ is RTâ‘ "
Thanks
