, first hop is our firewall (192.168.1.100), second hop is the DMZ interface (172.16.254.1) and then it reaches the device on other side of VPN (172.16.201.5)..
Thanks
					
				
			
			
				
			
			
				
			
			
			
			
			
			
		Hi,
this is an normal behavior when using unnumbered ipsec interfaces.
This KB article describes the behavior and how to "workaround" it if you want:
Regards,
bommi
NSE 4/5/7
| User | Count | 
|---|---|
| 2727 | |
| 1417 | |
| 810 | |
| 738 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.