SSLVPN not routing correctly for SSL VPN "Enabled Based on Policy Destination"
Hello,
we have SSL VPN enabled for our employees, based on policy destination.
with that we're routing only certain services via VPN to for example whitelist our public IP for services and make a service reachable for employees.
the rule contains an address group which contains several FQDNs.
The problem we see here randomly is that the firewall resolves 2 IPs for an FQDN, which is fine and intended, but the routing table on client side only contains 1 sometimes.
"suddenly" (without reconnecting or similar) the 2nd IP also appears in the routing table, but why? So randomly its working or not working to get routed via VPN.
As it is not working properly to route all needed traffic via our SSL VPN we added a 2nd rules directly below the main one.
that new rule should route all “amazon aws” traffic via VPN - this was implemented for testing and troubleshooting.
This rule does not get hit very often, assuming the routing table does not get populated with all routes, as routing all amazon-AWS traffic should cause quite a lot requests be routed via VPN.
How often does the vpn client of fortinet update the routing table and are there any limits of routes that can be set?


