Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
capricorn80
New Contributor II

Purpose of adding static route for ssl vpn subnet to ssl.root interface?

Hi!

 

I am running tunnel mode ssl vpn without adding static route of my SSL VPN subnet pointing to ssl.root and everything works fine.

 

whats the use of setting up this static route?

 

thanks

2 Solutions
Toshi_Esumi
Esteemed Contributor III

The reason is to allow inside devices/applications reach the clients from their ends. Especially when the client machine is running some UDP based applications connected to a server, which needs to send spontaneous updates or something periodically or on-demand, the server can't reach the client to deliver the UDP packets.

 

View solution in original post

Toshi_Esumi
Esteemed Contributor III

That's another reason if you have other routers/firewalls relying on redistributed routes from the FGT over a routing protocol, if the FGT is not their default GW.

View solution in original post

4 REPLIES 4
Toshi_Esumi
Esteemed Contributor III

The reason is to allow inside devices/applications reach the clients from their ends. Especially when the client machine is running some UDP based applications connected to a server, which needs to send spontaneous updates or something periodically or on-demand, the server can't reach the client to deliver the UDP packets.

 

capricorn80

ok Thanks for the information. I guess it can also be used for BGP rourte distribution?

Toshi_Esumi
Esteemed Contributor III

That's another reason if you have other routers/firewalls relying on redistributed routes from the FGT over a routing protocol, if the FGT is not their default GW.

Sloanstar
New Contributor

Maybe if you are running OSPF and redistributing statics and the FGT isn't on your default egress path?

 

Edit:

Sorry. I hadn't changed my view mode to flat, i thought this was unanswered.

Labels
Top Kudoed Authors