Fortigate replies to ICMP even though the best route is out another interface.
This is my first post here and wanted to clarify something in my head about the way Fortigate processes traffic.
I have the following topology. R1 ---- FGT ----R2 + this configuration:
-R1 and R2 both have 22.214.171.124/32 configured as Loopback interfaces.
-FGT has 126.96.36.199/32 configured as Loopback interface
-R1 has static route towards 188.8.131.52 via FGT
-R2 has default route via FGT
-FGT has default route via R1 and static route to 184.108.40.206 via R2.
If I try to ping 220.127.116.11, it works from both R1 and R2. I find that odd, given the fact that the best route towards 18.104.22.168 is via R2.
The only thing I could think is regarding the fact that when pinging from R1 (the one that should not work from my point of view), the FGT because it has loose RPF configured, it allows the traffic on that port and then when replying it does not consult the routing table and rather it sends the reply via the interface it received it. Can I have a confirmation about this behavior?