Skip to main content
amorales
New Member
June 22, 2020
Question

FortIoS 6.2.4 - SD-WAN Rules for self-originating traffic

  • June 22, 2020
  • 5 replies
  • 7560 views

Hi, we are having issues with DHCP Relay configured on FortiGate Firewall wish SD-WAN interface. We need to apply SD-WAN rules for DHCP relay traffic which is originated from Firewall using LAN interface IP but since 6.2.2, self-originating traffic does not match SD-WAN rules according to this document:

 

https://kb.fortinet.com/kb/documentLink.do?externalID=FD47380

 

Is there any way to force the FortiGate to apply SD-WAN rules for self-originating traffic? Thanks.

 

EDIT: Just to clarify, the issues we are having related to DHCP Relay are about DHCP request being sent through a different interface than we need (we are trying to force this traffic to go out through an interface with worse cost in SD-WAN virtual link) but the rule is not being applied for this traffic. So the issue is not really related to DHCP relay but SD-WAN rules not being applied to local traffic.

 

    5 replies

    emnoc
    New Member
    June 22, 2020

    Did you set the relay ip under the interface from cli?

     

    config sys interface

       edit port1

          # interface that you are relaying from

          set dhcp-relay ip x.x.x.x

     

    end

     

     

    Ken Felix

     

    amorales
    amoralesAuthor
    New Member
    June 22, 2020

    Hi, I did it from GUI but the result is the same:

     

    config system interface edit "port1" set vdom "root" set dhcp-relay-service enable set ip 10.10.10.1 255.255.255.0 set type physical set alias "LAN" set snmp-index 1 set dhcp-relay-ip "10.10.20.4"

     

    The thing is that I need that the traffic originated from 10.10.10.1 to 10.10.20.4 match a SD-WAN rule I have created for this traffic but this does not work. I think it is due to this change:

     

    https://kb.fortinet.com/kb/documentLink.do?externalID=FD47380

     

    Thanks for answer. 

    emnoc
    New Member
    June 24, 2020

    Self originating traffic should never match a SDWAN rule from my understanding. Why would you want that?

     

    Ken Felix

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!