Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
selassi
New Contributor

Interface routing to an offsite location

Good day engineers

 

I have a fortigate 900D which is connected thorugh an MPLS with service providers. however there is an offsite branch that houses the MX server and there is a fortigate there too. i have interface on the fortigate which is local to me and now my problem is making the service provider access the mail server on the offsite location. all traffic has to pass through my fortigate.

 

if i trace route to the fortigate itself im successful but if i try to traceroute to the specific interface, packets are dropped.

 

i am thinking of creating a policy route that can make the traffic move well.

 please if there is anyone who can assist me i will be grateful

 

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

You need to check if the route to the destination exists on your local FGT, then then route back to the source exists on the remote. If they do, check your MPLS network has both routes at the provider.

If you sniffed or ran flow debug at your local FGT, you probably already know where the packets are dropped.

For packets routed over MPLS network, not toward the internet, policy routes at edge devices wouldn't make much difference.

ericli_FTNT
Staff
Staff

Please try flow debug to see the reason why packets are dropped.

diag deb en

diag deb flow filter xx

diag deb flow trace start 3

 

Labels
Top Kudoed Authors