Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bidge
New Contributor

Policy Base Routing not Returning Traffic

We are trying to setup a PBR to send specific traffic from 1 host to another host over a IPSEC VPN instead of a metro-E link but are having a return traffic issue. We have fortigates at both ends of the tunnel and tried setting PBR in both. For the gateway, we are using the remote VPN IP and also have tried adding a static route at the same administrative number with a lower metric (lower priority). Kind of stuck as to if we are missing anything else needed for PBR to work and return traffic.

10.0.0.0.1 192.168.1.254
3 REPLIES 3
AEK
SuperUser
SuperUser

Can you share the policy routes and routing tables (CLI) from both FortiGates? You may hide sensitive info like public IP addresses.

AEK
AEK
amrit
Staff
Staff

Please follow this article and make sure tunnel IDs are added to the IPsec tunnel interfaces 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configure-policy-routes-for-route-based-in...

Amritpal Singh
rvillaroman
Staff
Staff

Hi @bidge ,

 

On your setup, you have Fortigate, where you set the PBR and static route with lower priority pointed to VPN. If you have control over the VPN peer device, kindly create a specific route pointed to the VPN for return traffic. By using PBR, we can only manipulate outbound traffic; for inbound traffic, you need to set a more specific route pointed to the VPN on your VPN peer device. If there is no specific route set, it will send on the WAN or on the interface the default route it pointed. 

 

Regards,

rvillaroman
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors