Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jd653687
New Contributor III

Routing goes wrong

Hello All,

I have a Site-to-Site VPN and when the VPN is not connected and we try to open a browser to open a site on the branche-office we get a time-out and when the vpn is rebuild and try again, we still get a time-out.  When debug this on the Fortigate we see that it is looking for an already made session and reuses that session again. But this session goes out over the WAN and not the VPN. We need to clear the session so it takes the right path.

The priority for the WAN is 10 and the VPN is 5. Running a Fortigate 51E with firmware 5.4.1

Is there a way to force the connection use the VPN route and not the WAN?

And if it uses the WAN connection and the VPN is reconnected then force the VPN path?

 

Thanks in advance.

4 REPLIES 4
Somashekara_Hanumant

Hi,

 

You can configure the policy route, please refer the below KB article.

 

http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD38790&sliceId=1...

 

Regards,

Somu

EMEA Technical Support
ede_pfau

No, "policy route" totally misses the point here.

 

You need to prevent the FGT from creating a session for traffic which is aimed at a VPN tunnel in the first place. The key here is "blackhole routing".

This has been discussed quite a few times in the forums. Please see https://forum.fortinet.com/tm.aspx?m=132141 for an explanation and the remedy.


Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
bommi

Hi,

 

you should configure blackhole routes for your subnets on the other site of your vpn tunnel.

The blackhole routes will stop the creation of sessions and no routes will be cached.

 

This KB will help you:

http://kb.fortinet.com/kb/documentLink.do?externalID=FD36695

 

Best Regards

bommi

NSE 4/5/7

NSE 4/5/7
jd653687

Thank you.

I created the Policy route. I will test. If this is not the result we are looking for I will have a look at the Blackhole option.

 

Labels
Top Kudoed Authors