Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MTrin
New Contributor

Policy Routes vs Firewall Policies

Hi there. I' m a bit new to Fortigate and have tried to search for this answer. I have a set of policy routes that go to a specific gateway not the default on routing table. Problem is, application filtering doesn' t work and firewall rules seem to be erratic. When I debug flow, all I see is the " find a route" fo the policy route but no fw policy being matched. So question is, does static route bypass all firewall rules? I don' t get it because it' s too erratic and debug doesn' t give me the information I want. Thanks for any help
3 REPLIES 3
Dipen
New Contributor III

No ! Static route will not bypass the Firewall Policy. Same is true for Policy route as well. Both Static Route and Policy Route require a Firewall Policy to work. Ideally only static route is required; a policy route is only required if we want a subset to override the static route.

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
MTrin
New Contributor

That' s what I thought. So what would explain traffic not matching any policy on debug? flow trace addr 192.168.121.123 all it says: find next route (the policy route) and application filter won' t work.. well I guess I will keep digging
emnoc
Esteemed Contributor III

So is the problem application filtering or the fwpolicy itself? Do you have a application filter applied to the firewall policy that' s in question? & ave you double check the fwpolicyID based on the debug flow output to ensure nothing e.g your ordering of the fwpolicies This might give you ideal as to you re-adjust the fwpolicies to match the policy-route interfaces & order and diag debug again and see if any thing improves.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors