FortiGate - Debug flow: "pre_route_auth check fail"

 Problem

You have configured a VIP object to allow an incoming connection. The object is configured correctly and there is a firewall policy for it.
However, the connection does not work.
In the "diag debug flow" the following error message appears:
"pre_route_auth check fail(id=0), drop"

Solution

In most cases there is something wrong with the routing:
- There is a route which does not correspond to the incoming interface.
- There is an interface (e.g. loopback) which includes the external IP address of the VIP object.

For detailed information about this there is a KB article from Fortinet.

Comments

Popular posts from this blog

FortiGate BGP dual-home with multiple ISP

FortiGate as DNS Server or DNS Proxy

FortiGate and Windows L2TP / IPsec with Split Tunneling