Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jonansondi
New Contributor

Transparent mode and asymroute

Hi, i have a fortigate configured in transparent mode and it has asymroute enabled (I have 2 routers as Internet Gateway.Some users use one router and others the other router) When i enabled protection profile (using web filter and antivirus) i experienced some issues with connection. Some users can navigate perfectly but other can' t navigate (webpage doesn' t load and fortigate warning is not shown). Ping works perfectly.When i disable protection profile all works ok. Could be any problem with this type of configuration?! Thanks.
2 REPLIES 2
tato
New Contributor

Hi Jonansondi, As far as i know, fortigate is running under stateful inspection. And when you enable asymroute, it means you disable stateful inspection. I think Fortinet will not recommend you to do this since most modern hacking attacks are commtted based on transaction based. A few month ago, i have the similar problem as yours. I' m using 2unit FG3040 (transparent mode) without HA. My case is, traffic send to fortigateA but reply packet send to FortigateB. At that time we decide to configure priority on our CoreRouter. I don' t know about you environment. But why are you disable stateful inspection? Thx tato
jonansondi
New Contributor

Hi hartato, thanks for your reply. We have 2 routers (A and B). All people in network has configured router A as Gateway and this router has a route-map to send traffic from some users to Router B. This users had the problem to navigate using protection profile. Finally we have used a DHCP server to assign corruptly gateway for each users. Now all works correctly.
Labels
Top Kudoed Authors