Hi,
in my environment i have 2 WAN interfaces with IPv6 and one LAN interface which is using that. The IPv6 addresses on the LAN are configured manually, and i use 2 policy routes to send LAN prefix A to WAN1 and LAN prefix B to WAN2.
All is working fine, i can access the internet, and i can access published services on the servers via IPv6 from outside.
Only one thing i don't get working:
From a Client/Server in prefix A access a client/server in prefix B.
So local routing when there are multiple IP addresses on a single interface.
From a client/server in prefix A network i can ping the FortiGate interface in prefix B, but no other client/server.
Where can i search, can i made a routing trace?
In a packet trace i see the incomming ICMPv6 with the comment (no response found!). Normal i will say it must be more than one packet:
request from client to fg
request from fg to destination
response from destination to fg
response ftrom fg to client
But only the first one is in the capture.
I have no denied traffic in the log...
Some ideas/hints where to search?
Kind regards
Stefan
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
On the same interface i have also 2 IPv4 Addresses, here the routing between that 2 networks is working normal...
O.k. i figured it out.
The policy routes are the problem.
So the question is, how can i control, that internal clients with prefix A will be routed through WAN1 and prefix B through WAN2? A solution will be 2 separate VLAN's, but perhaps there is a different solution with a single interface.
For outgoing traffic policy routes will work, but this overwrites local routes.
A policy route which except local routes will be perfect...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1679 | |
1085 | |
752 | |
446 | |
226 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.