Scenario Description:
1. Dual-link telecommunications links, mainly telecommunications (default route), Unicom supplemented
2. Internal part server requires external access, NAT to Telecom line
3. Requires that some users of the intranet will be able to access the internal server via the NAT Telecom public IP network (assuming
172.16.0.0/24)
4. Suppose that the network segment to be dispatched now is 172.16.100.0/22
This is the time to write a policy route:
routing, static and Policy Routing->create_new:
650) this.width=650; "title=" 1.png "style=" HEIGHT:323PX;WIDTH:584PX; "alt=" Wkiom1bfiwvxnrumaabs_gxctdg441.png "src= "Http://s1.51cto.com/wyfs02/M01/7B/05/wKiom1bFIWvxnruMAABs_gXctdg441.png" width= "844" height= "414"/>
After creating the above policy route, we went to test to find that 172.16.100.0/22 has been dispatched to the Unicom line,
However, a new problem has been created, and the 100.0/22 network segment cannot access the NAT telecom public network IP.
After several attempts, the following methods are finally implemented:
Also create a policy route, as follows
Incoming interface: Select Firewall Intranet Port
Destination Address: Enter the server network segment
Outgoing interface: Select Firewall intranet port 650) this.width=650; "title=" 2.png "style=" Height:293px;width:532px;float:none; "src="/HTTP/ S1.51cto.com/wyfs02/m00/7b/05/wkiom1bfi8sxsyuwaabo_lqussq605.png "width=" 722 "height=" 411 "alt=" Wkiom1bfi8sxsyuwaabo_lqussq605.png "/>
2. Create a firewall policy, the policy inflow interface must select any interface.
650) this.width=650; "title=" 3.png "style=" Height:273px;width:535px;float:none; "src=" http://s1.51cto.com/wyfs02/ M00/7b/05/wkiol1bfjcrc8fg-aaayxfpy7pg544.png "width=" 713 "height=" 307 "alt=" Wkiol1bfjcrc8fg-aaayxfpy7pg544.png "/ >
Through the above configuration, we find that the link exchange can be realized.
This article is from the "Stenning Technology blog" blog, make sure to keep this source http://magic3.blog.51cto.com/1146917/1742892
FortiGate Firewall Policy Routing configuration for dual-link visits