| Description | This article describes the reason why the traffic does not match the policy route which forwards traffic over IPsec tunnel. |
| Scope | FortiGate. |
| Solution |
On FortiGate, it is configured a policy route to forward traffic over a site-site IPsec tunnel but traffic is not matching as expected.
With this policy route in place, traffic from 10.0.0.5 to the Internet should be routed over an IPsec tunnel named 'dial'. However, the debug flow shows that traffic is using wan2:
2024-01-08 11:10:48 id=20085 trace_id=10 func=print_pkt_detail line=4368 msg="vd-root received a packet (proto=1, 10.0.0.50:53807->8.8.8.8:8) from interface. code=8, type=0, id=53807, seq=7811."
Verify the policy route, here there is no policy route matching:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.