| Description | This article describes that for some scenarios, there is a requirement to route public IP toward any specific tunnel. |
| Scope | FortiGate. |
| Solution |
Traffic topology :
10.10.10.10 (Private IP) --- FGT A --- (IPSEC) --- Router/Firewall --- (Public IP) 20.20.20.20.
Here: 10.10.10.10 is the Private IP. 20.20.20.20 is the Public IP.
It is necessary to verify that IPsec is up on both sides and that both IPs 10.10.10.10 and 20.20.20.20 are in Phase 2 selectors on both sides.
Then, create the static route with a lower Administrative Distance than the Default Route.
config router static edit "5" (5) # show
Now, it is possible to configure the policy route, to make sure traffic coming from 20.20.20.20 toward 20.20.20.20 always uses the IPsec interface:
config router policy edit "1" (1) # show
It is possible to further verify with the command get router info command to see the routing status:
It is possible to see that 20.20.20.20 is known through the tunnel interface as required. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.