Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Returning Traffic

FG60B WAN1 y WAN2, each one configured with different IP address. No Load Sharing Nor Link Redundancy, but just migrating external IP address for external applications (the current access is through an ISP on WAN1 and needs to be changed to the second ISP on WAN2) Duplicated Policies are OK Both gateways are set in Static Routing Table (one per interface). No priority set. How can I tell which interface is using an incoming connection to return? I would like to make it return through the interface it used to in
7 REPLIES 7
laf
New Contributor II

You said you have two static routes. Are both using the same metric? Check in the Router --> Monitor and see what routes you have there.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
rwpatterson
Valued Contributor III

When a session is opened from the node, it should be returning on the same policy. If it' s new traffic, it may be using a different one.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Not applicable

The routes are using the same metric because I dont want to force an outgoing interface, so the connections coming from WAN1 should go back through WAN1, and those coming from WAN2 should return through WAN2 The question is, how can I check if this is happening or, in other words, how can I tell which interface is using the FG to return incoming traffic?
laf
New Contributor II

diagnose sniffer packet wan1 ' host x.x.x.x' and then move to that x.x.x.x site and see what s happening.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.

The most expensive and scarce resource for man is time, paradoxically, it' s infinite.
Not applicable

Hi, I also have a problem like that, but with just one route marked as default. Is there some way to force traffic returns to the incoming interface? That interface where traffic comes is not default GW. ex: Default gw to wan2 and traffic incoming from wan1. I need traffic returns to wan1. Thanks, Paulo Sousa
rwpatterson
Valued Contributor III

When traffic goes out wan2 to say...eBay.com. eBay only knows where the return address is (because you have to NAT it to get out the door), not you' re wan1 address, so of course it' s going back to wan2. The only way would be to create a NAT pool, and force outgoing traffic to have the other interface' s (wan1) IP address, but I' m not sure how sound that practice would be, or if it would even work as desired. Good luck

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
support12

Hi if traffic is coming from wan1 it would exit wan1 on the return. The firewall do not follow the router behavior it is different in that scenario.
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors