Hello,
Normally when a packet comes to FortiGate, firewall follows the way
What about the answer packet that comes to same session ? Here is the scenario
1- I sent a FTP Put Request to a server, that packets goes over the firewall
2- Firewall process the first packet based on the the parallel path processing like in the link that i have shared. Create a session and sent packet out to FTP Server based on routing table
3- Then server response with FTP Put Response, paket goes over firewall to FTP client again
--> at this third step how does firewall process packet ? I believe it checks the session first and when there is a session how is the next steps ? do we have a link that fortigate shows that? Because i believe that packet will be forwarded out of interface that packet comes to firewall and does firewall check in session details ? then look at the routing table ?
As i said i need a link or explanation about processing steps of the return packets in a FortiGate
When it returns to the FortiGate, the firewall verifies that a response packet for an already-established session matches the packet with the current session. Upon identifying the session, the firewall proceeds to forward the packet by utilizing the pre-existing session data, including policies and routing. The packet is routed out of the interface it entered if it matches an already-open session. Any security checks that are required, like DoS prevention, IP header verification, and policy enforcement, are carried out via the firewall. Next, the packet is sent to the right place using the routing table as a required security checks
Hello Spoojary,
Thank you for your answer. So at this case, does Firewall checks routing table/ fib -> forwarding base to see outgoing interface and review the route info.
What would be the case if the scenario looked like this?
1- "Upon identifying the session, the firewall proceeds to forward the packet by utilizing the pre-existing session data, including policies and routing. The packet is routed out of the interface it entered if it matches an already-open session."
2- But the route to desination address of the response indicates another interface...
I believe in this scneario firewall chooses route interface ?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.