Skip to main content
Cochino44
Explorer
July 7, 2022
Question

VLAN DMZ ERROR RULES

  • July 7, 2022
  • 2 replies
  • 1034 views

 

Hello evryone, here i'am with this next issus. We are working in the fortinet client with acces to the internet , but we cant get out to IP 185.103.36.109. According to the menssage we have problem in the policies but ours policies its fine, from 192.168.77.4 to 185.103.36.109

 

func=vf_ip_route_input_common line=2596 msg="find a route: flag=80000000 gw-185.103.36.109 via root"
id=20085 trace_id=3008 func=fw_local_in_handler line=432 msg="iprope_in_check() check failed on policy 0, drop"

 

What do you think about this? , do you need any more about this problem? 

 

Ty a lot

2 replies

akristof
Staff
Staff
July 7, 2022

Hello,

Do you have this 185.103.36.109 as VIP or IPPOOL configured?

ntaneja
Staff & Editor
Staff & Editor
July 7, 2022

Hi @Cochino44

 

func=vf_ip_route_input_common line=2596 msg="find a route: flag=80000000 gw-185.103.36.109 via root"---FGT is trying to send traffic to itself as its searching route via root(this means that this public IP is configured in some part on FGT)
id=20085 trace_id=3008 func=fw_local_in_handler line=432 msg="iprope_in_check() check failed on policy 0, drop"

 

Doc for error:
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-debug-flow-messages-iprope-in-check-check/ta-p/190119

 

Thanks

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!