FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
skaneria
Staff
Staff
Article Id 198041
Description
This article describes the message 'pre_route_auth check fail(id=0), drop' while accessing the VIP over SSL VPN debug.

Solution
It is not possible to access the VIP over the SSL VPN.
This happens when multiple ISP and VIP are configured to access the resources.

For example, VIP is configured on 'Port2'.




Firewall has 2 ISP configured on 'Port1' and 'Port2', however SSL VPN policy is from ssl.root to 'Port1' as below.





If user try to access the resource over port 4433, it will not be accessible and debug will show 'pre_route_auth check fail(id=0), drop' error.

Resolve this by changing the outgoing interface to 'Port2' in the SSL VPN policy.





Contributors