Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Dipen
New Contributor III

Static Route using IPSEC VPN Virtual Interface [FortiOS 5.0.x Vs FortiOS 5.2.x]

Hi

I was running FortiOS 5.0.7 where we had a DialUP IPSEC VPN Gateway Configured. We were able to add Static Routes with IPSEC Interface as Device.

However after upgrading to FortiOS 5.2.3 we are unable to add a Static Route using IPSEC Interface as Device. As such we are unable to add routes to our Remote Sites.

 

Thanks & Regards

Ahead of the Threat. FCNSA v5 / FCNSP v5

Fortigate 1000C / 1000D / 1500D

 

Ahead of the Threat. FCNSA v5 / FCNSP v5 Fortigate 1000C / 1000D / 1500D
3 REPLIES 3
vjoshi_FTNT
Staff
Staff

Hello Dipen,

Showing the virtual IPSec interface in the static route , virtual wan link and the link monitor is not expected and is fixed in V5.2.3.

 

Logically, this Dynamic IPSec interface should not be part of the static route/VWL and link monitor.

When the dialup user connects, there is a route added automatically by the kernel.

 

Hope that answers your query

hallodri

Hi,

 

for the correct routes being added to a dial up vpn connection you have to configure the networks you need to be routet as VPN phase 2 SA (remote network and local network).

As soon as the vpn tunnel goes up the routes will be added to the forwarding table. You'll find them as static routes when you have a look at the routing monitor.

I hope this helps...

ede_pfau
SuperUser
SuperUser

In other words, you don't need to configure static routes in advance. Traffic for these destinations will be routed correctly IF and when the tunnels are up.

 

BTW, this behavior is not new, seen it in v4.3 at least. Might have been a bug in the GUI that you were able to select the tunnel IF in Static Routes.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors