Hello guys,
I have an issue with a PBR. I don't think it is working or may be I didn't configured it well.
I have a route pointing to subnet 10.0.0.0/8 via port1 and I have an out of band mgmt interface mgmt1 192.168.1.1 that should directly be reachable from a machine in the subnet 10.0.0.0/8 (please see the image).
I see ping from 10.1.1.1 to mgmt1 but the packet are dropped "reverse path check fail".
I created this PBR :
incoming int : mgmt1
src : 192.168.1.1
dst : 10.1.1.1
outgoing int : mgmt1 (it should go back from the same interface)
gateway : 192.168.1.254
I still have the reverse path check fail :(
any ideas? thank
Are there mutliple routes to the network? Could return traffic be taking an alternate route?
Mike Pruett
based on the attached diagram, correct firewall policies (mgmt-port1, port1-mgmt) could handle the traffic to the right path.
Fortigate Newbie
User | Count |
---|---|
2119 | |
1187 | |
770 | |
451 | |
345 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.