| Description | This article describes the behavior when using automation Sitch it is not possible to use source IP. |
| Scope | FortiGate. |
| Solution |
When the Automation stitch executes the FTP backup and the remote server is through an IPsec VPN, the FortiGate will use the Wan IP of the FortiGate to perform the connection.
Follow sniffer as example:
filters=[host 10.19.131.120]
By default, the local out traffic uses the interface IP of lowest index value, hence the source is showing as 192.168.1.10.
Due to Phase 2 selectors or routing from the other site this could impact the FTP connection. To correct this, an IP address in the VPN interface can be configured.
config system interface
The sniffer shows the IP used for the connection of the VPN.
filters=[host 10.19.131.120]
Note: This is the expected behavior, it is not possible to configure source IP in the FTP connection. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.