- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Need Routing Help
Im troubleshooting this connection ============ |
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @HeshanDeeyagaha,
Your first troubleshooting step should be collecting a packet flow debug while generating the affected traffic. Feel free to share the output here if needed.
Example:
diagnose debug enable
diagnose debug flow filter addr 10.15.1.1
diagnose debug flow show function-name enable
diagnose debug flow show iprope enable
diagnose debug flow trace start 5
Useful resources:
https://docs.fortinet.com/document/fortigate/6.2.15/cookbook/54688/debugging-the-packet-flow
Boris
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
As Boris mentioned, first run debug flow where we will see exactly which policy route and which route was selected. Then, for further analysis we will need a bit more details about the config and routing.
get router info routing-table all
diag firewall proute list
diag sys sdwan service
diag sys sdwan member
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Guys, will get this on non-prod and see check for what you have asked.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I think I have your wording confused. You say VPN traffic never hits your router (the pfsense box)? If that's the case then pfsense would just need a static route to know how to route traffic to get to the VPN network.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sir I think you are commenting on the wrong thread. no VPN, No pfSense