Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
saitoh
Collaborator

icmp timeouts with PRB

Hi all,

 

I hesitate to ask this because I think this is quite elementary, but I need a bit of explanation.

I am testing how policy based routing works in CP, wanting to make CP route packets to eth0 or eth2, according to what a certain packet is.

The environment as follows.

image.png

FortiGate has allow-all policy, no UTM activated.

GW1, 2 play role of cluster of ClusterXL.

image.png

Here eth1 is in trusted zone, eth0, eth2 untrusted.

Default route is set on eth0, and only HTTPS to FGT's external IP (10.11.124.1) goes to eth2 by policy based routing.

 

The test above was successful.

I made changes to routing policy for only ICMP to go through eth2, which failed due to timeouts.

I am not experienced enough to understand what is happening.

 

I believe this is quite basic networking topic, not the one of CP...

I feel sorry to ask this stupid question, but your comments would be highly appreciated.

 

Saitoh

sliver bullet: casting repero or tossing it into the harbor
0 Kudos
3 Replies
Chris_Atkinson
Employee Employee
Employee

What is the source & destination IP addresses of your test traffic?

(Note a limitation is that traffic originated from the gateway itself is not subject to PBR).

CCSM R77/R80/ELITE
0 Kudos
Lesley
Leader Leader
Leader

Do you have something configured like

 static-route {...} ping {off | on}?

gateway can use ping to monitor gateways. Maybe this options influences your test with ping? 

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_Advanced_Routing_AdminGuide/T...

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
the_rock
Legend
Legend

No issues man, we are here to help. What do you see if you do basic capture? Do the logs show anything?

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events