I upgraded to FortiOSv4.0,build0458,1106
27 (MR3 Patch 1) on our central Fortigate router.
An Auto Key (IKE) IPSec VPN is configured over the WAN.01 link.
I recently phisically reconnected the WAN.01 link from port11 to port15 on the central FGT to increase performance, since only ports[12..15] use FortiASIC HW acceleration.
This involved replicating FW rules, routing and other settings from port11 to port15.
As a result, I cannot change the "Local Interface" under phase1 settings.
When I try to switch from port11 to port15 I get the message:
"Invalid IP range
I set the administrative and link status of port 11 to "down".
This is the private range I use for the remote Fortigate units:
config router static
set device "to Spokes"
set dst 192.168.0.0 255.255.0.0
The local subnet for the central Fortigate is set to 192.168.1.0/24.
Another consequence of switching ports is that now the majority of outgoing network traffic from local LAN is flowing through the WAN.02 link which is located on port12, even though port11 is selected in phase1 configuration. FW policy statistics show around 500000 packets for port15 and 60 million packets on port12.
The destination address in phase2 quick mode selector on the remote fortigate units is set to:
I unset all load balancing related weight settings on all interfaces.
What is eluding me here?
Any help is greatly appreciated.