I do ping 10.103.248.44 and the ping is reply, when i do sdwan failover i can see the ping is always timeout.
We must change the ping to other host example 10.103.248.45 and the ping is reply.
Seem the fortigate icmp session to 10.103.248.44 is cached and will be reply if the cache was refreshed.
Anyone know how we can fix this?
Can you share the output:
show full sys global | grep snat
the result is "set snat-route-change disable"
Can you enable it and try again?
event the traffic is no natted?
In that case, forget about it.
so have other idea?
Can you check if preserve-session-route is enabled for each SD-WAN interface members?
You may check firewall-session-dirty as well.
User | Count |
---|---|
2249 | |
1223 | |
772 | |
451 | |
366 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.