Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
smxko
New Contributor II

Why does this work without asymmetric routing?

Hi,

we have two /29 IP blocks from our ISP. IPs from the first block are used for SNAT and a few VIPs. There are two default routes, one for each gateway because both subnets have different gateways. We didn't want ECMP, so we increased the distance for the default route to the gateway of block 2.

We also run VIPs on IPs of the second block. I was wondering why this is even working because the default route for block 2 is not installed in the routing table because of the higher distance. Therefore, return traffic for VIPs of block 2 must flow through the gateway of block 1. Asymmetric routing is disabled, I checked it.

We are also using port forwarding on the VIPs, so it shouldn't automatically use the VIP's public IP for return traffic.

 

Edit: I checked the session table and it looks like Fortigate SNATs the reply traffic. But I don't know why, the documentation says that it sould only be doing this when One-to-One NAT is applied without port-forwarding. Or does this rule only apply to traffic originating from the server behind the VIP and not reply traffic?

2 REPLIES 2
Dhruvin_patel

Greetings!

 

FortiGate is a stateful firewall.

When FortiGate receives the traffic, it creates a session, and the return traffic is sent based on that created session. 

When the packet enters the FortiGate, it will follow the flow defined in this document, https://docs.fortinet.com/document/fortigate/6.4.0/parallel-path-processing-life-of-a-packet/86811/p... and create the session.

The traffic below to the same session will be sent out using the session info.

As a result, in your case, the traffic received on another block will create a session and then return the allowed/routed based on the created session. 

 

Best Regards!

If you have found a solution, please like and accept it to make it easily accessible for others.

 

Dhruvin Patel
dingjerry_FTNT

Hi @smxko ,

 

Your description is ambiguous. 

 

It's better you share relevant configurations for better understanding.  And if you can provide with a network diagram, it would be much better.

Regards,

Jerry
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors