Description |
This article discusses an issue where IPsec over TCP does not work properly when FortiGate is configured with more than one WAN interface.
The problem occurs because returning IKE traffic is taking a different path instead of the source path, resulting in asymmetric behavior, causing the IKE over TCP not to function properly on any tunnel or interface. |
Scope |
FortiGate v7.4.7 and v7.4.8 with dual WAN and equal default routes using IKE over TCP. |
Solution |
Symptoms:
Reproduction Scenario:
Workaround: The issue can be mitigated by enabling 'system.ike-policy-route' and configuring a route policy for TCP IKE traffic. This forces IKE over TCP traffic to return through the same WAN interface.
Step 1: Configure the Router Policy. Access the CLI and configure the following:
Step 2: Enable IKE Policy Route. Enable IKE policy routing:
Related article: Technical Tip: Asymmetric traffic observed with IPsec over TCP in an SD-WAN dual WAN setup |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.