Hi,
I need to configure policy-based routing and I'm testing it, but it doesn't work even though the configuration is correct.
According to a veteran's advice, I temporarily enabled asymroute, and when I immediately disabled it, the routing started working.
I'm reluctant to use this method. Is this a well-known workaround?
Do you have any advice on a better way to handle this?
Hardware: FortiGate 120G OS: 7.4.8
Thanks,
Kenji
Hi Kenji
Asymmetric routing is a workaround not so good for security. It was a good technique in ancient world network but it should not be use anymore if you want a good network security.
The right solution is either redesign your network architecture to avoid the need for asym routing, or you can also use auxiliary sessions instead, which is secure (may also need some redesign).
Have a look here:
Hope it helps.
Until you share the topology, hopefully with a diagram, around the policy route you intended to steer traffic to a specific direction including the policy route itself, we can't comment why it's not working.
Toshi
User | Count |
---|---|
2561 | |
1357 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.