FortiGate—Local_Traffic_SDWAN_Behavior

Situation

[1]
# Static Route設定上是0.0.0.0/0給三個SDWAN Zone,路由使用SDWAN rule來判斷
The configuration assigns 0.0.0.0/0 to three SD-WAN zones and routing is determined by SDWAN rules.

[2]
# Email(fortinet-notifications.com)沒辦法走正確的介面出去
Email(fortinet-notifications.com) is unable to use the correct interface.

[3]
# 沒有辦法指定SMTPS使用set interface-select-method specify,
It’s not possible to configure SMTPS to use [set interface-select-method specify].

Solution

[1]
Login FortiGate WebUI

[2]
# 新增靜態路由
Network > Static Routes > Add New > Destination[FQDN][fortinet-notifications.com]

Conclusion

# SDWAN rules不同於Policy Route
SD-WAN rules differ from policy routes. 

# 需要依賴底層的靜態路由,也沒有辦法處理Local Traffic的路由
Rely on underlying static routes and cannot handle local traffic routing.

# 除非那一個服務能透過[set interface-select-method specify]方法指定Local Traffic要怎麼走
Unless [set interface-select-method specify] method can be used to define how local service is routed.