Question
SSL VPN and dual WAN / default routes
I' ve got a problem with my SSL VPN connections... I' m running a Fortigate 500A, with two WAN links (T1, DSL) and one internal network link. SSL VPN worked fine until I added the 2nd WAN link, and added a 2nd default route to allow web load sharing between it and the pre-existing T1. Both static routes are: 0.0.0.0/0.0.0.0 > T1 router IP 0.0.0.0/0.0.0.0 > DSL router IP After tweaking route order and priority, I was able to get web traffic to prefer the DSL route as I wanted, without having to use any policy routes. But why is this breaking the return traffic to my SSL VPN tunnel clients? They can connect via the browser interface, but then are dropped within 30 secs, with no traffic ever received back from the firewall. Obviously, it' s being routed out the wrong gateway (DSL). Any ideas?
