This is a debug trace on port 3389 when I try and RDP in on the 2nd ADSL connection.
Is the highlighted line the issue?
capetown (root) # id=36870 trace_id=16 func=resolve_ip_tuple_fast line=3403 msg=" vd-root received a packet(proto=6, 196.211.62.91:53784->196.214.69.107:3389) from dmz."
id=36870 trace_id=16 func=resolve_ip_tuple line=3526 msg=" allocate a new session-000405b4"
id=36870 trace_id=16 func=get_new_addr line=1755 msg=" find SNAT: IP-192.9.200.200(from IPPOOL), port-3389"
id=36870 trace_id=16 func=fw_pre_route_handler line=127 msg=" VIP-192.9.200.200:3389, outdev-dmz"
id=36870 trace_id=16 func=__ip_session_run_tuple line=1853 msg=" DNAT 196.214.69.107:3389->192.9.200.200:3389"
id=36870 trace_id=16 func=rpdb_srv_match line=423 msg=" Match policy routing: to 192.9.200.200 via ifindex-9"
id=36870 trace_id=16 func=ip_route_input_slow line=1267 msg=" reverse path check fail, drop"
id=36870 trace_id=17 func=resolve_ip_tuple_fast line=3403 msg=" vd-root received a packet(proto=6, 196.211.62.91:53784->196.214.69.107:3389) from dmz."
id=36870 trace_id=17 func=resolve_ip_tuple line=3526 msg=" allocate a new session-000405b5"
id=36870 trace_id=17 func=get_new_addr line=1755 msg=" find SNAT: IP-192.9.200.200(from IPPOOL), port-3389"
id=36870 trace_id=17 func=fw_pre_route_handler line=127 msg=" VIP-192.9.200.200:3389, outdev-dmz"
id=36870 trace_id=17 func=__ip_session_run_tuple line=1853 msg=" DNAT 196.214.69.107:3389->192.9.200.200:3389"
id=36870 trace_id=17 func=rpdb_srv_match line=423 msg=" Match policy routing: to 192.9.200.200 via ifindex-9"
id=36870 trace_id=17 func=ip_route_input_slow line=1267 msg=" reverse path check fail, drop"
id=36870 trace_id=18 func=resolve_ip_tuple_fast line=3403 msg=" vd-root received a packet(proto=6, 196.211.62.91:53784->196.214.69.107:3389) from dmz."
id=36870 trace_id=18 func=resolve_ip_tuple line=3526 msg=" allocate a new session-000405b8"
id=36870 trace_id=18 func=get_new_addr line=1755 msg=" find SNAT: IP-192.9.200.200(from IPPOOL), port-3389"
id=36870 trace_id=18 func=fw_pre_route_handler line=127 msg=" VIP-192.9.200.200:3389, outdev-dmz"
id=36870 trace_id=18 func=__ip_session_run_tuple line=1853 msg=" DNAT 196.214.69.107:3389->192.9.200.200:3389"
id=36870 trace_id=18 func=rpdb_srv_match line=423 msg=" Match policy routing: to 192.9.200.200 via ifindex-9"
id=36870 trace_id=18 func=ip_route_input_slow line=1267 msg=" reverse path check fail, drop"
--
riaan
Fortigate 80c - 4.0 MR2 patch 7