Created on 07-14-2024 09:42 PM Edited on 08-25-2024 10:51 PM By Jean-Philippe_P
Description |
This article describes the conflict in VIP configuration. |
Scope | FortiGate. |
Solution |
The following error may be observed under certain conditions while configuring a VIP.
The extip is overlapped with the gateway of static route.
Although there is no static route manually created with the gateway IP overlapping with the external IP being used in the VIP configuration, this issue could still arise due to various reasons. A few examples are provided below.
Example 1:
show full-configuration | grep -f x.x.x.x <----- Replace x.x.x.x with the external IP.
FortiGate # get router info routing-table static | grep f 192.168.64.1
The above output shows that the external IP is being used as a gateway of a route for an IPsec tunnel.
name=Switch-FGT ver=1 serial=1a4a 66.x.x.x:0->63.y.y.y:0 tun_id=192.168.64.1 tun_id6=::192.168.64.1 dst_mtu=1500 dpd-link=on weight=1
Since the tunnel ID is set to 192.168.64.1, the static route is using this tunnel ID as the Gateway IP for the IPSec route.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.