Skip to main content
selassi
New Member
June 5, 2018
Question

Interface routing to an offsite location

  • June 5, 2018
  • 2 replies
  • 2950 views

Good day engineers

 

I have a fortigate 900D which is connected thorugh an MPLS with service providers. however there is an offsite branch that houses the MX server and there is a fortigate there too. i have interface on the fortigate which is local to me and now my problem is making the service provider access the mail server on the offsite location. all traffic has to pass through my fortigate.

 

if i trace route to the fortigate itself im successful but if i try to traceroute to the specific interface, packets are dropped.

 

i am thinking of creating a policy route that can make the traffic move well.

 please if there is anyone who can assist me i will be grateful

 

    2 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    June 5, 2018

    You need to check if the route to the destination exists on your local FGT, then then route back to the source exists on the remote. If they do, check your MPLS network has both routes at the provider.

    If you sniffed or ran flow debug at your local FGT, you probably already know where the packets are dropped.

    For packets routed over MPLS network, not toward the internet, policy routes at edge devices wouldn't make much difference.

    ericli_FTNT
    Staff
    Staff
    June 5, 2018

    Please try flow debug to see the reason why packets are dropped.

    diag deb en

    diag deb flow filter xx

    diag deb flow trace start 3