Hello,
we have establish GRE tunnel between a mikrotik and fortigate and we can ping both side of tunnel and we establish bgp over tunnel and announce a /24 to mikrotik now everything is ok and when i do packet capture i see incoming packets from GRE tunnel but they can not reach out from fortigate so in route policy i have add this kind of rule:
FG1 # show router policy config router policy edit 2 set input-device "LAN" set dst "1.2.3.0/255.255.255.0" set gateway 172.16.206.1 set output-device "GRETUNNEL" next
but its not working so when my lan users that has 1.2.3.0/24 can not use 172.16.206.1 as next-hop,
any idea how solve this?
and there is another note that when i have add my own static ip in static route for example add 9.8.7.6 as static route that set next-hop 172.16.206.1 from 9.8.7.6 i can reach whole network of 1.2.3.0/24
thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1643 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.