Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hmx8
New Contributor II

Does the Fortigate session-descriptor contain routing info?

 

Well, I got the following question from a customer with regards to re-routing WAN traffic to a backup Nessus in case the primary Nessus went down: "Does the Fortigate session-descriptor contain routing info? (Does a change in next hop mean a session-drop?)"

 

Scenario is that the next hop from pov of the FortiGate changes (OSPF/BFD in use). I need to admit that I really can't tell for sure whether or not the session descriptor contains routing info. Any hint?

 

Thanks and regards,

Holger

 

 

2 REPLIES 2
Jeff_FTNT
Staff
Staff

You may check it with CLI:

 dia sys session list session info: proto=17 proto_state=01 duration=3 expire=176 timeout=0 flags=00000000 sockflag=00000000 sockport=0 av_idx=0 use=3 origin-shaper= reply-shaper= per_ip_shaper= ha_id=0 policy_dir=0 tunnel=/ vlan_cos=0/255 state=log may_dirty npu npd none statistic(bytes/packets/allow_err): org=124/2/1 reply=367/2/1 tuples=2 speed(Bps/kbps): 142/1 orgin->sink: org pre->post, reply pre->post dev=5->7/7->5 gwy=192.168.70.1/192.168.1.12 hook=post dir=org act=snat 192.168.1.12:53655->172.16.100.80:53(192.168.70.60:53655) hook=pre dir=reply act=dnat 172.16.100.80:53->192.168.70.60:53655(192.168.1.12:53655) misc=0 policy_id=2 auth_info=0 chk_client_info=0 vd=1 serial=00669024 tos=ff/ff app_list=0 app=0 url_cat=0 dd_type=0 dd_mode=0 npu_state=0x100000 npu info: flag=0x00/0x00, offload=0/0, ips_offload=0/0, epid=0/0, ipid=0/0, vlan=0x0000/0x0000 vlifid=0/0, vtag_in=0x0000/0x0000 in_npu=0/0, out_npu=0/0, fwd_en=0/0, qid=0/0 no_ofld_reason:  offload-denied helper

FortiGate check routes firstly, then create session based policy. If routes is change, new session will recreate , thanks.

emnoc
Esteemed Contributor III

If a route changes from  the pov of the  fortigate and a new route is installed and it's anew interface the  existings session probably would not be recreated but dropped and then the next new SYN will craft a 2nd new session using the new interface in the RIB

 

just my hunch but you could test this or monitor by using a session filter.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors