Inter-VLAN routing issues - FortiGate
Hello everyone,
Before implementing the following configuration in production I'm testing it out in GNS3 and I'm facing issues with Inter-VLAN routing. I have configured FortiGate to act as router-on-a-stick.
- I have created VLAN 100 and VLAN 200 on the switch and allowed it over the trunk interface that is connected to the FortiGate. Configured the ports connecting the end devices as access ports.
- Created same VLANs on the FortiGate and attached it to the interfaces that is connected to the switch.
- Created the required Firewall polices, VLAN 100 -> VLAN 200 and VLAN 200 -> VLAN 100.
- From device in VLAN 100, I'm able to ping the VLAN 100 SVI IP address and the SVI IP address on VLAN 200. But unable to reach the other device in VLAN 200 and vice-versa.
- Packet sniffer on FortiGate shows that It is receiving the packet on VLAN 100 interface but it is not sending it out of VLAN 200 interface.
Please, find the attached images for the reference. I believe I'm not missing anything here. Any suggestions would be helpful.
Network Diagram:

Firewall Polices:

VLAN Interface details:

Sniffer Output:

Thank you
IMPORTANT UPDATE:
Hey everyone,
This is important I guess,
I just replaced the new FortiGate running FortiOS 7.2 with ForiOS 6.4.9. And, Inter-VLAN routing is happening now without any problem.
I have same configuration in place like the one that I had earlier.
Is this a bug or anything in 7.2 release? Can the Fortinet staff confirm this please?
Please find my updated screenshots:

PC1 to PC2:

PC2 to PC1:

Thank you



