Two Internet connections, can't get a VIP on the second one to work
This seems like it would be so simple, but I've been trying all week to get a VIP from the static pool on our second ISP connection to work.
Yesterday I broke out the diagnose debug flow filter and started looking at traffic sent to the VIP. I'm getting "reverse path check fail, drop"
So it looks like the Fortigate is getting traffic on the VIP on the second ISP connection, then trying to route it back out our primary ISP. I guess that makes sense, as the default route is set to the primary. So Reverse Path Forwarding must be dropping the packets.
But what do I need to do to get this working? Get a default route to the secondary ISP in the routing table?