Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Searchingforanswers
New Contributor

Dynamic Routing on a FG 3960E

Hello, I'm new here and have a problem (of course ;) ) We're working on a new setup that is using 2 3960E (FortiOS 6.0.6) in an ACTIVE/STANDBY HA. I've attached a very rudimentary design that hopefully helps to understand what I'm trying to describe. The FWs are connected via OSPF to 2 multilayer switches via 2 transfer VLANs. The clients in this setup use the Firewall as a Gateway und the multilayer switches are gateways (HSRP) for the servers. The whole setup is a 100% symmetric which means that both transfer VLANs are in the routing table of the firewall with the same metric and distance. With ECMP active we have some weird effects regarding dynamic routing: When a client tries to reach a server, i.e. ping, the connection can take either VLAN towards the server and come back over the other VLAN. This behaviour itself is not unusual and actually desired but the Fortigate behaves weird when this happens. First of all the fortigate does not produce a log entry for this connection only for the ones where both packets take the same way. Secondly there is no NPU offloading for this session. Mind you the ping still works but the behaviour is still bothersome. For other connection types (i.e. HTTPS) we sometimes witness unsuccessful connections when dynamic routing is active, whenever we deactivate one of the transfer VLANs everything works a ok again but this can't be the solution. I hope I was able to describe our issues and hope somebody has an idea of how we can tackle this beast. Thank you so much

 

Kind regards

 

Searchingforanswers

2 REPLIES 2
emnoc
Esteemed Contributor III

What does "diag debug flow" show you. The issues seem to be related to session monitor and possible spoof'ing due to the nature of the traffic and 2 paths.

 

Can you possibly use SDWAN here ? If answer ="NO" Any reason as to why not ?

 

I think "ECMP" has it benefits but here I would not use it.

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Searchingforanswers

Hi Ken, thank you for your reply. Which benefit would we have using SDWAN? We do have to use OSPF because later we will connect some other branches that already are using ospf and we would like the firewall to distribute the client networks that are directly connected. We specifically want to use ECMP to distribute the load.

 

Thanks a again

Labels
Top Kudoed Authors