Description | This article describes an issue where the reply traffic for Virtual IP (VIP) egresses from a different interface when a security profile(UTM) is enabled in the VIP firewall policy that uses proxy-based inspection mode. |
Scope | FortiGate v7.4.2, v7.4.3. |
Solution |
After upgrading FortiGate to v7.4.2, and v7.4.3, Virtual IPs do not work when UTM is enabled in the firewall policy with proxy-based Inspection mode. The problem can be verified by examining the logs as outlined below. Packet sniffers will show that the FortiGate responds to the client-initiated traffic, but it is routed via a different interface than the original incoming interface. Thus, the reply traffic does not arrive on the client machine. Sniffer output from non-working scenario:
Sniffer output from the working scenario when UTM is disabled in the firewall policy or when the firewall policy is in flow-based Inspection mode:
This issue has been resolved in v7.4.4 Workaround:
OR.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.