Message meets Alert condition
The following critical firewall event was detected: Routing information changed.
date=2021-11-22 time=17:18:52 devname= devid= eventtime= tz="-0400" logid="" type="event" subtype="system" level="critical" vd="root" logdesc="Routing information changed" name="Check_Office365" interface="wan2" status="down" msg="Static route on interface wan2 may be removed by health-check Check_Office365. Route: (X->Y http-down)"
Hi DarkNareh
This probably means that you have health-check or link-monitor to a specific server (should be http) and the server is failing.
Hello @DarkNareh
This log entry is alerting you to a critical event where the routing information on the wan2 interface has changed, potentially due to a health-check operation named Check_Office365. The route in question appears to be related to HTTP traffic (http-down).
Please review the configuration of your firewall and routing settings to understand the changes that triggered this event. Verify whether the routing change was intentional or if it indicates a potential issue or misconfiguration
@DarkNareh, In addition to the previous reply the log stated the interface wan2 might be down and that is used for Microsoft. It could be possible the SDWAN is configured in your environment and it is load balancing the traffic.
Hi there,
In addition to previous reply, please refer to this document to verify link-monitor configuration "https://community.fortinet.com/t5/FortiGate/Technical-Tip-Link-monitor/ta-p/197504"
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1751 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.