| Description | This article describes the issue of SD-WAN rules with application-based routing not working on FortiGate version 7.6.4 and provides a step-by-step guide to troubleshoot and resolve the issue. |
| Scope | FortiGate. |
| Solution |
The SD-WAN rules are configured with the application-based destinations, and the traffic matching these applications is not being routed through the intended SD-WAN rules.
To troubleshoot the issue of SD-WAN application-based routing not working on FortiGate version 7.6.4, follow these steps:
Despite the configuration, traffic destined for the YouTube application does not match the SD-WAN rule and is routed via the default SD-WAN rule instead.
SD-WAN rule:
config system sdwan config service end
config firewall policy end
Routing is already configured and functioning as expected. Traffic forward logs confirm that the application is correctly identified by Application Control.
Traffic destined for YouTube is not matching SD-WAN rule ID 2 and is instead matching a lower-priority SD-WAN rule.
By executing the command 'diagnose sys sdwan internet-service-app-ctrl-list', no learned application entries are displayed in the SD-WAN application control cache.
As there are no learned app entries in the SD-WAN app-ctrl cache, traffic cannot match SD-WAN rules configured with application-based destinations. As a result, the traffic does not hit the intended SD-WAN rule.
config ips settings
After making the above changes, the SD-WAN application ctrl list learned the entries, and the traffic will hit the expected SD-WAN rule:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.