Description |
This article describes the case when traffic destined to the limited broadcast address 255.255.255.255 is dropped by the FortiGate with the error 'iprope_in_check() check failed on policy 0, drop'. |
Scope | FortiGate. |
Solution |
By design, FortiGate operating in NAT mode does not allow/forward the traffic destined to 255.255.255.255. As a result, the following error is expected to appear in the debug flow traces. id=20085 trace_id=3955 func=print_pkt_detail line=5851 msg="vd-root:0 received a packet(proto=17, 10.10.79.2:5050->255.255.255.255:5050) tun_id=0.0.0.0 from internal3. " id=20085 trace_id=3955 func=__iprope_check_one_policy line=2027 msg="checked gnum-10000f policy-4294967295, ret-matched, act-accept" The setting 'set broadcast-forward enable' is not applicable for forwarding the traffic destined to 255.255.255.255. config system interface edit "internal3" set ip 10.10.79.1 255.255.255.0 set broadcast-forward enable next
The article Forwarding IP broadcast to a different network is an example use case of the broadcast-forward option. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.