Hot!Can not ping between local VLAN after setup Policy Route

Author
longtran.cntt
New Member
  • Total Posts : 12
  • Scores: 0
  • Reward points: 0
  • Joined: 2019/06/05 05:03:22
  • Status: offline
2020/11/19 21:40:30 (permalink) 6.2
0

Can not ping between local VLAN after setup Policy Route

Hi all,
 
I have 3 WANs, 2 local network VLANs (LAN-Office, LAN-Server (server1, server2)).
 
I've already configured like below:
  • WAN1, WAN2, and WAN3 are connecting to the internet successfully.
  • WAN1 is for VLAN-Office. WAN2 is for server1. WAN3 is for server2.
  • Policy Routes:
    • The office is going out to the internet through the interface WAN1.
    • The server1 is going out to the internet through the interface WAN2.
    • The server2 is going out to the internet through the interface WAN3.
    • Firewall Policy (IPv4 Policy) to allow the LAN-Office to access the LAN-SERVER) 
 
The issue is:
  • Scenario 1: If I put all the LANs into 1 interface only (for example WAN1), and disable 2 other WANS interfaces => the LAN-Office and LAN-Factory can ping the LAN-Server (server1 & server2).
  • Scenario 2: If I separated the LAN-Office into WAN1, server1 into WAN2, server2 into WAN3 and apply the Policy Route => the LAN-Office can not ping the LAN-Server (server1 & server2).
Please note that in both scenarios, I always keep enabling the Firewall Policy (IPv4 Policy) that allow LAN-Office to access LAN-Server (server1 & server2).
 
How can I fix the issue of pinging between LAN-Office and LAN-Server in the scenario2?
 
Thank you.


If I disable those port of WAN2 and WAN3 (red box), only enable WAN1 (green box)


And also disable the Policy Route here (red box)



And keep the Firewall Policy as the image, the LAN-Office can ping the LAN-Server (server1 & server2). 
 
If I re-enable the policy that disabled in the images above, then the LAN-Office can not ping the LAN-Server (server1 & server2)
 
My target is: LAN-Office is on WAN1, LAN-Server (server1 is on WAN2, server2 is on WAN3), and the LAN-Office can ping the LAN-Server (server1 and server2).
post edited by longtran.cntt - 2020/11/19 22:04:31
#1

2 Replies Related Threads

    Toshi Esumi
    Expert Member
    • Total Posts : 2339
    • Scores: 227
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: online
    Re: Can not ping between local VLAN after setup Policy Route 2020/11/20 09:21:00 (permalink)
    0
    I can't tell for sure since I almost never use policy routes, other than SD-WAN. But the first policy route LAN-Office -> WAN1 for all (0/0) must be taking away traffce to server interfaces. To test it, just disable only that policy route to see if you can ping the server.
    Then if that's the case set the priority number on the default route toward WAN2 and WAN3 lower so that WAN1 has the lowest number (default=0) so that LAN-Office traffic takes that default route and remove the first policy route.
     
    Policy routes are sticky. Regardless the interface is up or down, they're always evaluated before looking up the routing table. Then if the destination is "all" 0/0, it would take all traffic away. I think SD-WAN's rules (=policy routes) works a little differently thus always works better for most situations.
    #2
    SmokeyMountian Tech
    New Member
    • Total Posts : 16
    • Scores: 0
    • Reward points: 0
    • Joined: 2020/07/13 13:06:17
    • Location: East Tennessee
    • Status: offline
    Re: Can not ping between local VLAN after setup Policy Route 2020/11/20 21:19:06 (permalink)
    0
    Do you have Static routes set with the same Distance for each WAN connection?
    Make sure your primary WAN connection has the lowest priority EG, 0 and then your other wan connections are 1 or higher.
    You'll then want to enable advanced routing under the Settings / Features.
    Then program Policy routes to specify server1 as the source and forward traffic to proper WAN port. Make sure you use the gateway IP for the WAN connection that your using.
    https://kb.fortinet.com/kb/documentLink.do?externalID=FD46603
     
    If you need to set up any incoming traffic you can setup VIP's (Virtual IP's)
    #3
    Jump to:
    © 2020 APG vNext Commercial Version 5.5