Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SOC_Reply
New Contributor

Static routing entry missing from routing table

Hello, anyone of you bump into a situation like this: - added one static entry on the " static route" entry on VDOM root - destination interface is an IPSec tunnel so, if you issue the " get router info routing-table all" on the CLI, the above mentioned static entry does not appear. The device is a Fortigate 620b with a 4.0 MR2 release. Thanks in advance for any help provided.
7 REPLIES 7
emnoc
Esteemed Contributor III

Is that ipsec tunnel up ? I think if the tunnel is down, the route would be squashed.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
SOC_Reply

Yes, the tunnel is up and some other traffic is passing into it.
rwpatterson
Valued Contributor III

You will only see a route if the tunnel was created in interface mode. Policy mode tunnels use other methods for routing. (Smoke and mirrors is my guess....)

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
SOC_Reply

Well, the tunnel is in interface mode. The weird situation is that other static route having the same destination (the tunnel interface) are working fine. Only the last i inserted is not accepted by the Fortigate.
ede_pfau
SuperUser
SuperUser

Strange that you see " some other traffic passing into it" . Either you need a route to pass traffic, or the route is not in the r. table and traffic does not pass -? Please give more information about the intended traffic and the route(s) you' ve configured. And the matching Quick Mode selectors in phase2.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
SOC_Reply

The context is more complex than i told; the Fortigate 620b act as a VPN concentrator for many IPSec L2L VPNs. The above mentioned VPN was previously configured and is working fine for other 3 networks that are located on the remote end of the VPN. All three networks are addressed each one with a static route having the tunnel interface as destination. Now, we added a new network on the remote end and thus a new static route on VPN concentrator. Note that the first 3 static route and the new one are not consecutive and i have almost 140 static routes configured on VPN concentrator. Quick mode selectors are 0.0.0.0/0.0.0.0 for both source and destination. Thanks again.
SOC_Reply

Hi all, just to close the topic...a reboot solved the problem...
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors