pjhtech Tools
FortiGate

FortiGate Policy Routing Between VDOMs Fails RPF

Fix an inter-VDOM policy-routing RPF drop when a suitable kernel return route cannot be used, with an exception on the receiving VDOM link.

A policy route between VDOMs can match the intended path while traffic is dropped with reverse path check fail, drop. RPF uses kernel routes, not policy routes; adding a policy route does not create the kernel route back to the packet’s source.

If the VDOM-link design requires policy routing and cannot use a suitable kernel return route, disable RPF on the receiving VDOM-link interface.

Alternative: add the missing kernel return route

If a static return route fits the design, keep RPF enabled. For a source network behind VDOM-A’s 10.255.0.1/30 link, VDOM-B needs a route back to 192.0.2.0/24 via 10.255.0.1 on vlink-B. Run this inside VDOM-B:

Configuration change • example route in VDOM-B
config router static
    edit 0
        set dst 192.0.2.0 255.255.255.0
        set gateway 10.255.0.1
        set device "vlink-B"
    next
end

edit 0 creates a route. Edit the existing route ID instead if it only has the wrong gateway or interface.

Use get router info routing-table details 192.0.2.10 and get router info kernel to check the installed return path. Feasible RPF accepts a feasible path through the incoming interface; strict RPF requires the best path there. strict-src-check disable selects feasible RPF and does not disable RPF.

If a route is displayed but its ingress path is absent from the kernel, compare route selection and the documented ECMP installation limit.

References