Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
wcente
New Contributor

FGT40C 4 MR3 Patch 7

Hi there, strange, I' ve got an FGT 40C with 4 MR3 Patch 7 and there' s noch policy routing visible in the webgui. Any hints? regards Sebastian
9 REPLIES 9
rwpatterson
Valued Contributor III

Has this unit been configured already, or is it a new install? If new, flatten, reload firmware via TFTP. If already in service, I don' t know. (see prior line... Schedule some down time.) My advice. Perhaps it' s simply a browser issue? Have you tried another?

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Paul_Dean
Contributor

Hi Sebastian, I think this is normal. I' ve checked on one of our FG40C and there is no Router section in the GUI. You can set a Default Gateway and routes under System-->Network-->Routing. If you login to the CLI the routing commands still seem to be there: fw01 # show router ? access-list access list configuration access-list6 ipv6 access list configuration aspath-list AS path list configuration auth-path auth-based routing configuration bgp router bgp configuration community-list community list configuration gwdetect gwdetect isis router isis configuration key-chain Key-chain configuration multicast router multicast configuration multicast-flow multicast-flow configuration ospf router ospf configuration ospf6 router ospf6 configuration policy policy routing configuration prefix-list prefix list configuration prefix-list6 ipv6 prefix list configuration rip router rip configuration ripng router ripng configuration route-map route map configuration setting set router settings static routing table configuration static6 routing table configuration fw01 #
NSE4
NSE4
wcente
New Contributor

Hey there, thanks for quick reply! I already figured out that via CLI policy routes still can be set, if it works: don' t know. But I am wondering about that it disappeared, using earlier releases it is still there. Unfortunally I now have to configure some devices and it would have been kind to do so via webgui. We brought out those boxes and now I have to policy route out traffic for some subnet areas using double wan interfaces... Edit: The boxes are widely spread around and already in use by customers :) Edit: I rebootet one -> the same, I enabled everything in admin settings -> the same, I tried Firefox and IE from different computers -> the same
rwpatterson
Valued Contributor III

Have you checked the release notes for that version? They may say something about features removed from the GUI.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Paul_Dean

If you have a spare (not FG40C) firewall in your lab you could configure policy routing in the GUI and then just copy and paste it from the config to the FG40C. If you are not sure what you need to do then I' m sure someone on this forum can help you.
NSE4
NSE4
rwpatterson
Valued Contributor III

 config router policy
     edit 0
         set input-device " internal" 
         set src xxx.xxx.xxx.xxx 255.255.255.0
         set dst yyy.yyy.yyy.yyy 255.255.255.0
         set output-device " wan2" 
     next
     edit 0
         set input-device " internal" 
         set dst xxx.xxx.xxx.xxx 255.255.255.0
         set output-device " wan1" 
     next
     edit 0
         set input-device " internal" 
         set src 192.168.1.0 255.255.255.0
         set gateway 192.168.1.1
         set output-device " vpn_tunnel" 
     next
 end
 

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
wcente
New Contributor

That' s indeed a good idea, I' m going to have a look at it now...
wcente
New Contributor

Thankyou all, but well, there is really no problem for me doing it via cli, I just wonder why the hell it disappeared from the gui and what intention lays behind this decision! I didn' t find anything in the release notes down till patch 5 regarding this... But thanks a lot for your really nice wish to help! So maybe it appears somehow in the future again, or it even doesn' t, who knows? ;)
ADN
New Contributor

The release notes of v4.0 MR3 Patch 7 indicate that removing the Router option from the menu is a design change. ' 169906 Remove dynamic routing from FortiGate 40C series Web-based Manager.'
Labels
Top Kudoed Authors