Hi,
Whether a GRE interface can be added to SDWAN member interface??
Currently we have a scenario, where forward traffic will be sent our through one physical interface (Internet) and return traffic will be through GRE built on top of same physical interface. By default with firewall behaviour this packet will be dropped, hence we are exploring on adding this GRE interface to SDWAN member interface to avoid this situation.
Regards
Raja
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
GRE can be added as SDWAN member, but I don't think it is going to help in the specific condition you are referrring.
https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/942095/sd-wan-members-and-zo...
In your scenario the traffic will be considered asymmetric and will still be dropped. Do you know why the return traffic is coming on GRE instead of the original interface? May be fixing the route issue on peer side is better option.
ref: https://community.fortinet.com/t5/Support-Forum/Fortigate-same-zone-but-different-interface-packet-p...
We have an external security services which inspects all return traffic and hence GRE tunnel from that device to Fortigate device. But I guess, SDWAN interfaces will be consider as one single logical interface and if bundle GRE interface into SDWAN , it wont consider it as asymmetric traffic.. Because in SDWAN sometimes when link is not performing well, forward traffic might take that overlay path and return traffic comes in a different overlay path.. Hence I am assuming that within SDWAN member interfaces will be considered as symmetric flow.. Please clarify my understanding
Regards
Raja
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.