Hi guys!
Im running on a 200D (5.4.2) WAN LLB. Before this I had a SSLVPN, not split tunneling, to route all the internet traffic through the fortigate when connected. After the implementation of the WAN LLB Im not able to create a policy from ssl.root to WAN LLB.
Any idea?
Regards,
--
Changuelco
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi Changuelco, WLB is a virtual interface and cannot support this configuartion as well policy route . I suggest to you to create a policy from ssl.root to one of the 2 wan interfaces and perform a policy route in order to route this traffic to internet ( example src ssl.subnet dst 0.0.0.0 0.0.0.0 to wan1). additional policy route should be added before this in order to stop the policy route for your local subnets .
That should be great... the only thing is when the WLB is configure, the interfaces attached to the WLB are not available to be selected on a firewall policy...
Did you ever find a solution to this @changuelco?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.