Policy routing enhancements in the reply direction
When reply traffic enters the FortiGate, and a policy route or SD-WAN rule is configured, the egress interface is chosen as follows.
With auxiliary-session enabled
in config system settings
:
- Starting in 6.4.0, the reply traffic will not match any policy routes or SD-WAN rules to determine the egress interface and next hop.
- Prior to this change, the reply traffic will match policy routes or SD-WAN rules in order to determine the egress interface and next hop.
With auxiliary-session disabled
in config system settings
:
- The reply traffic will egress on the original incoming interface.