Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mortirolo
New Contributor

VDOM default route

Currently all my static routes have a distance of 10 including the default route. I would like to lower the distance on the default route down to 5, reason been someone added an additional default route by mistake. When this happened most of the traffic traversed the new default route which had a distance of 10....going to a black hole. My plan is to lower the correct default route on the slim chance this happens again, this way the default route with the lower distance (5) would win. Does lowering the default route distance to 5 cause any issues when all other static routes are 10 distance, I wouldn' t imagine so but thought I would share this post.
6 REPLIES 6
emnoc
Esteemed Contributor III

Good ideal , but a flawed approach. Why not set it at 1, 2, 3, or 4? And what keeps some from one from looking at the existing default and not copying it. You need to correct the admin/engineer that added a 2nd default-route without reviewing the need or the existing default route imho.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
emnoc
Esteemed Contributor III

oh to ask the other question, no a default route of 5 4 3 2 1 will effect a static route of 10. A routing is by most specific So a route to 0.0.0.0/0 dist 5 will not be impacted by a more specific route to 192.168.10.0/24 wit a dist of 2 If the packet matches the dest of 192.168.10.0/24 and it' s in the route table, no more matching takes places.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
mortirolo

Hi, your answer is not too clear for me I want to know if you set the default route with a distance of 5 or lower, will the more specific routes that have a distance of 10 (not 2 as you stated) will used if packets match these specific routes?
mortirolo
New Contributor

Also fyi - the administrator created a default route by mistake instead of clicking cancel, when you create a default route from FortiManager it defaults to interface ssl.vdom, if you create a default route from the Fortigate Firewall directly it defaults to your external interface (v4.2) The admin created the default route from FortiManager
emnoc
Esteemed Contributor III

I want to know if you set the default route with a distance of 5 or lower, will the more specific routes that have a distance of 10 (not 2 as you stated) will used if packets match these specific routes?
A routing is by most specific Read the above line again that I bold out & what I posted earlier. The most specific route ( not a default ) will not be impacted by the default. e.g ( a route to a destination 192.168.1.122 ) Firewall has the following; 0.0.0.0/0 next-hop gw 1.1.1.1 distance 5 and 192.168.1.0/24 next-hop gw 1.1.1.2 distance 1 The latter is the most specific regardless of the distance. Is that clear?

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
mortirolo
New Contributor

yes, thanks
Labels
Top Kudoed Authors