amirimran's Posts

Thanks @Benjaman for the explanation. The same Business Policy is being used for other spokes. We don't have a specific rule for that application "Microsoft Office 365" but we do have the rule for "I... See more...
Thanks @Benjaman for the explanation. The same Business Policy is being used for other spokes. We don't have a specific rule for that application "Microsoft Office 365" but we do have the rule for "Internet" destination backhauling to the Hub. It's just weird to me that only this spoke is having issue connecting to the destination IP address while the other spokes are working fine. For the other spokes, the Route is only showing "Branch to Backhaul" for that destination IP address. That is the only difference I can see. Back to the Flow table of the problematic spoke, if the route to 52.123.128.14 is learned from other Branch, shouldn't the Next Hop showed the Branch Edge name instead of the Hub for flow that is showing "Branch to Branch"? This is another thing that confused me.  I will try your suggestion playing around with the Business Policy and see what the results are. Thanks!!
Hi @Benjaman , Attached is the screenshot. Just noticed that for some flows, it is also not showing the link info. Is this normal?
Hi,  I have a setup of hub and spoke where internet traffic will go via hub's internet link. One of the spoke (Spoke1) is showing the Next Hop as the hub (eg: Hub1) but the Route are 2 different typ... See more...
Hi,  I have a setup of hub and spoke where internet traffic will go via hub's internet link. One of the spoke (Spoke1) is showing the Next Hop as the hub (eg: Hub1) but the Route are 2 different types; 1 is Branch to Branch and the other is Branch to Backhaul. This is for the same source and destination IPs. When I checked the other spokes (Spoke2 and Spoke3) for the same destination IP (which is Microsoft public IP), the flow report is showing the Next Hop as the hub (Hub1) but there's only 1 type of Route which is Branch to Backhaul. Right now, Spoke1 is having issue connecting to that Microsoft public IP. I can also see the Fortigate firewall log that we put between Hub1 and ISP link, that the traffic to that Microsoft public IP is showing as "IP connection error" which seems to suggest asymmetric routing. Spoke1, 2 and 3 are all using the same profiles so I am currently stuck as why Spoke1 is seeing 2 different type of Route for the Next Hop Hub1. I am inclined to think that the different type of Route is causing the issue in Spoke1. Appreciate any help