Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
robinh007
New Contributor III

SIP Traffic Routing Issue

Hi,

 

We are observing that traffic is being routed to the internet unexpectedly. To restore connectivity, we need to manually clear sessions each time, which is not normal behavior.

 

What would be the root cause of why the traffic is being forwarded to the internet instead of the intended path. Suggest a permanent fix to avoid the need for manual session clearing.

 

Expected Route: Port3
Source: 10.1.17.0/24 & 10.1.24.0/23
Destination: 10.201.0.0/16

 

 

Here is the sniffer.

 

diagnose sniffer packet any "host 10.201.11.149" 4 0 1
interfaces=[any]
filters=[host 10.201.11.149]
0.094933 port3 in 10.202.11.149.5065 -> 10.1.26.78.5060: udp 978
0.151538 port3 in 10.202.11.149.5065 -> 10.1.26.78.5060: udp 979
0.197107 port3 in 10.202.11.149.5065 -> 10.1.26.78.5060: udp 980
0.200285 port3 in 10.202.11.149.5065 -> 10.1.24.78.5060: udp 978
0.320295 port3 in 10.202.11.149.5065 -> 10.1.24.78.5060: udp 976
0.381149 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 980
0.398419 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 980
0.431817 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 980
0.462804 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 978
0.480379 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 978
0.538935 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 980
0.645899 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 976
0.728746 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 979
0.825621 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 979
0.833834 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 978
0.885002 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 980
0.963385 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 978
1.091788 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 978
1.151664 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 979
1.200736 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 978
1.227192 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 980
1.288029 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 979
1.334484 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 1161
1.347026 port3 in 10.201.11.149.5065 -> 10.1.24.78.5060: udp 1163

 

 

#Fortigate

 

RH007
RH007
1 REPLY 1
funkylicious
SuperUser
SuperUser

hi,

is the destination for 10.201.0.0/16 via port3 with a static route or learned via a dynamic routing protocol ? a flap/port down would explain a sudden lost route and use the default path.

i would suggest adding a static route with priority 250 with next-hop Blackhole, so then when a flap or something happens with port3 traffic destined for that subnet will not go via the default gw/INET but rather to balckhole/be dropped.

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors