Description
This article describes how to configure a static route with address objects or address groups.
Scope
FortiGate.
Solution
Configure a standard address through the GUI under Policy & Objects, specifying the name, type, and subnet:
GUI view:

edit "Test_range"
set uuid 1e123290-e041-51e9-b531-e5c4e2980e1a
set subnet 10.0.0.0 255.255.255.0
next
end

edit "Test_group"
set uuid dd0497ce-e041-51e9-1b4e-bc11d7cc083c
set member "Test_range"
next
end

edit "Test_range"
set uuid 1e123290-e041-51e9-b531-e5c4e2980e1a
set allow-routing enable
set subnet 10.0.0.0 255.255.255.0
next
end

edit "Test_group"
set uuid dd0497ce-e041-51e9-1b4e-bc11d7cc083c
set member "Test_range"
set allow-routing enable
next
end
edit 1
set dstaddr
<string> please input string value
Test_range address
Test_group addrgrp
set dstaddr


edit 1
set gateway 192.168.1.1
set device "wan1"
set dstaddr "Test_group"
next
end
From FortiOS v7.4.0, it is possible to define a preferred source IP for static routes to control the source IP used for local-out traffic. This setting allows better control over the source IP on egress interfaces, making it feasible to use a specified IP instead of the default interface IP.
config router static
edit <id>
set preferred-source <ip_address>
next
end
This configuration allows local-out traffic using the static route to use the preferred source IP instead of the IP associated with the egress interface.
Verification:
get router info routing-table details 10.0.0.0
Routing table for VRF=0
Routing entry for 10.0.0.0/24
Known via "static", distance 10, metric 0, best
* vrf 0 192.168.1.1, via port1
Note: To add the address objects in a group, either disable or enable static route configuration for all of the address objects in the same group. The parameter static route configuration must be disabled or enabled in the same way.