We are trying to setup a PBR to send specific traffic from 1 host to another host over a IPSEC VPN instead of a metro-E link but are having a return traffic issue. We have fortigates at both ends of the tunnel and tried setting PBR in both. For the gateway, we are using the remote VPN IP and also have tried adding a static route at the same administrative number with a lower metric (lower priority). Kind of stuck as to if we are missing anything else needed for PBR to work and return traffic.
Can you share the policy routes and routing tables (CLI) from both FortiGates? You may hide sensitive info like public IP addresses.
Please follow this article and make sure tunnel IDs are added to the IPsec tunnel interfaces
Hi @bidge ,
On your setup, you have Fortigate, where you set the PBR and static route with lower priority pointed to VPN. If you have control over the VPN peer device, kindly create a specific route pointed to the VPN for return traffic. By using PBR, we can only manipulate outbound traffic; for inbound traffic, you need to set a more specific route pointed to the VPN on your VPN peer device. If there is no specific route set, it will send on the WAN or on the interface the default route it pointed.
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.