Hi, we have a fortigate 60D.
 
 I have an access point who must report to a wireless controller on another subnet 
 going through the fortigate.
 
 Route are OK as other devices can route traffic just fine between the 2 subnet.
 
 It seems the broadcast from the access point to discover the wireless controller
 are blocked...
 
 Here is the result of the debug trace :
 
 id=13 trace_id=200 msg=" vd-root received a packet(proto=17, 172.25.18.206:38212->255.255.255.255:38212) from internal." 
 id=13 trace_id=200 msg=" allocate a new session-00000663" 
 id=13 trace_id=200 msg=" iprope_in_check() check failed, drop" 
 
 Why is it blocked?
 How Can I allow that traffic?
 
 Both subnet are reachable via the " internal"  interface of the fortigate.
					
				
			
			
				
	Frank