Well, I got the following question from a customer with regards to re-routing WAN traffic to a backup Nessus in case the primary Nessus went down: "Does the Fortigate session-descriptor contain routing info? (Does a change in next hop mean a session-drop?)"
Scenario is that the next hop from pov of the FortiGate changes (OSPF/BFD in use). I need to admit that I really can't tell for sure whether or not the session descriptor contains routing info. Any hint?
Thanks and regards,
Holger
You may check it with CLI:
dia sys session list session info: proto=17 proto_state=01 duration=3 expire=176 timeout=0 flags=00000000 sockflag=00000000 sockport=0 av_idx=0 use=3 origin-shaper= reply-shaper= per_ip_shaper= ha_id=0 policy_dir=0 tunnel=/ vlan_cos=0/255 state=log may_dirty npu npd none statistic(bytes/packets/allow_err): org=124/2/1 reply=367/2/1 tuples=2 speed(Bps/kbps): 142/1 orgin->sink: org pre->post, reply pre->post dev=5->7/7->5 gwy=192.168.70.1/192.168.1.12 hook=post dir=org act=snat 192.168.1.12:53655->172.16.100.80:53(192.168.70.60:53655) hook=pre dir=reply act=dnat 172.16.100.80:53->192.168.70.60:53655(192.168.1.12:53655) misc=0 policy_id=2 auth_info=0 chk_client_info=0 vd=1 serial=00669024 tos=ff/ff app_list=0 app=0 url_cat=0 dd_type=0 dd_mode=0 npu_state=0x100000 npu info: flag=0x00/0x00, offload=0/0, ips_offload=0/0, epid=0/0, ipid=0/0, vlan=0x0000/0x0000 vlifid=0/0, vtag_in=0x0000/0x0000 in_npu=0/0, out_npu=0/0, fwd_en=0/0, qid=0/0 no_ofld_reason: offload-denied helper
FortiGate check routes firstly, then create session based policy. If routes is change, new session will recreate , thanks.
If a route changes from the pov of the fortigate and a new route is installed and it's anew interface the existings session probably would not be recreated but dropped and then the next new SYN will craft a 2nd new session using the new interface in the RIB
just my hunch but you could test this or monitor by using a session filter.
PCNSE
NSE
StrongSwan
User | Count |
---|---|
2046 | |
1169 | |
770 | |
448 | |
339 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.