Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AlbMin
New Contributor

static route inactive?

Hello,

we have a Fortigate 600D

I've created a new IPSec Tunnel, and, for this tunnel, a static route. But the static route is not active. I can't see it under Monitor > Routing Monitor.

With the command "get route info routing-table all" the static isn't shown, too.

With the command "get route info routing-table all" the static route is shown as inactive:

S 10.231.154.0/24 [10/0] is directly connected, VPN_Test inactive

 

If I change the the device from the static route to an already for a long time existing VPN, the route is working.

 

Thank you

AlbMin

3 REPLIES 3
Iescudero
Contributor II

Hey there!

First, I think that's because you use get router info routing-table database instead get route info routing-table all. This KB may help you: http://kb.fortinet.com/kb/documentLink.do?externalID=FD36417

Second, a route is inactive when is invalid for using it. Every route must fulfill with some rules to the Fortigate could use it.

You could check this KB from fortinet: 

http://kb.fortinet.com/kb/documentLink.do?popup=true&externalID=FD30119&languageId=

 

I'm not entirely sure, but i think your VPN is down.

 

Check your VPN status and when is up, your route would be active.

 

Hope it helps!

emnoc
Esteemed Contributor III

If the phase1 is not up the route would be inactive.

 

 

diag vpn tunnel list  and diag vpn gateway will show your ipsec tunnel is down.

 

Also the get router  details will show this also;

 

i.e

get router  info routing-table   details 192.18.245.99/32

Routing entry for 192.18.245.99/32   Known via "static", distance 10, metric 0     directly connected, evpntst inactive

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
AlbMin
New Contributor

Hello,

 

thanks for answers. You're right, the relevant VPN tunnel was never up. But the VPN tunnel I changed to for testing, was'nt up at the moment, too. But of course he was already activated in the past. Perhaps that's the decisive difference.

Just in this moment the tunnel goes up first time and now the static route is active. Great.

Thanks a lot

Greetings

AlbMin

Labels
Top Kudoed Authors