Skip to main content
Source Link
Zac67
  • 92.2k
  • 4
  • 76
  • 144

By default, a Fortigate firewall uses stateful inspection of each connection. Since several gateways are involved, I very much suspect asymmetric routing, with the reverse path bypassing the Fortigate. This makes stateful inspection fail, resetting the connection.

You need to either switch off stateful inspection (reverse path forwarding) or make sure that the routing path matches in both directions.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Details-about-FortiOS-RPF-Reverse-Path-Forwarding/ta-p/190100?cmd=displayKC&externalId=FD30543

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-the-FortiGate-behaves-when-asymmetric-routing/ta-p/198575