FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rsondal
Staff
Staff
Article Id 273785
Description This article discusses static route confusion while using DHCP on a WAN interface.
Scope FortiGate.
Solution
  1. A static route is created under Network -> Static Routes but still, it shows showing wrong administrative distance when checking the route.

 

image1.JPG

 

image2.JPG

 

  1.  So, AD distance has been set to 10 on the static route on GUI but it is showing 5 on the CLI when the routing table is checked.
  2.  Why is it taking AD distance 5 as compared to AD 10 because a lower distance will be the priority in the static route.
  3. It is because DHCP has been enabled on the WAN interface which has the option enabled: 'Retrieve default gateway from server'. It will have a default gateway automatically, and AD by default is 5.

 

image3.JPG

 

  1. The route is already present on the routing table, but to use a static route with AD distance 10, it is possible to change the interface as well or just disable the option default gateway from the server on the WAN interface and it will show the static route with AD 10 set manually on the static route under network.
  2. This will also help when failover is set between 2 WAN connections. In the failover, it is necessary to set the same AD and the priority should be different which can be done on a static route under the network.