Hi, We have an unnumbered IPSEC interface type VPN between a Juniper and Fortigate. Its been working fine for ages. Now when we do a trace route from the Juniper end the management interface on the Fortigate shows in the response as part of the route. This is playing havoc with various path monitoring devices (and we are getting random disconnects now). The thing is this may have been introduced since the upgrade to 5.2.1 - is anyone else seeing this? Tech support says its due to the index of the interface and we have to use numbered IPsec tunnels - but why now! TAC' s response tells me that Fortigate effectively do not support unnumbered IPSEC interface tunnels as far as I am concerned.
Richard