Description |
This article describes how to troubleshoot when traffic does not match SD-WAN rules. |
Scope | FortiGate. |
Solution |
To make sure SD-WAN rules work, there must be a route in the routing table for that destination. If there is no route to the corresponding destination in the routing table, SD-WAN rules will not trigger.
For example: An SD-WAN rule has been created as below:
The source is 'all' and the destination is '1.2.3.4', but there is no valid route for '1.2.3.4' in the routing table:
If a user attempts to go through '1.2.3.4' in this scenario, traffic will not be routed to port1 as per the SD-WAN rule.
To avoid this scenario, first create a static route to that destination toward the expected interface as shown in the following image:
The route will pop up as shown in the following image:
After making this change, the SD-WAN rule will receive hits as intended. |