Skip to main content
blackmetal
New Member
September 6, 2018
Question

PBR Not working for tunnels

  • September 6, 2018
  • 0 replies
  • 2126 views

Hello,

we have establish GRE tunnel between a mikrotik and fortigate and we can ping both side of tunnel and we establish bgp over tunnel and announce a /24 to mikrotik now everything is ok and when i do packet capture i see incoming packets from GRE tunnel but they can not reach out from fortigate so in route policy i have add this kind of rule:

 

FG1 # show router policy config router policy edit 2 set input-device "LAN" set dst "1.2.3.0/255.255.255.0" set gateway 172.16.206.1 set output-device "GRETUNNEL" next

 

 

but its not working so when my lan users that has 1.2.3.0/24 can not use 172.16.206.1 as next-hop,

any idea how solve this?

 

and there is another note that when i have add my own static ip in static route for example add 9.8.7.6 as static route that set next-hop 172.16.206.1 from 9.8.7.6 i can reach whole network of 1.2.3.0/24

thanks

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!