{"id":1378,"date":"2026-09-10T01:51:16","date_gmt":"2026-09-09T20:21:16","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/"},"modified":"2026-09-14T04:31:05","modified_gmt":"2026-09-13T23:01:05","slug":"fortigate-policy-route-configuration-with-dual-isp-real-life-examples","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/","title":{"rendered":"FortiGate Policy Route Configuration with Dual ISP Real-Life Examples"},"content":{"rendered":"<p>Managing internet traffic across multiple Internet Service Providers (ISPs) requires precise routing controls. Standard routing lookups only consider the destination IP address. However, modern enterprise networks often require routing decisions based on source IP, port numbers, or ingress interfaces. Master proper <strong>FortiGate policy route configuration<\/strong> to gain granular control over outbound paths without complex routing protocols.<\/p>\n<p>In this comprehensive guide, you will learn how Policy-Based Routing (PBR) operates on FortiOS. You will configure policy routes to steer business-critical application traffic through a secondary ISP line while sending standard employee browsing through the primary link. We will cover prerequisites, GUI and CLI configuration steps, packet flow mechanics, verification commands, and troubleshooting workflows.<\/p>\n<h2>Real-Life Scenario: Multi-ISP Traffic Steering<\/h2>\n<p>Consider a medium-sized enterprise operating a local branch office. The site maintains two distinct internet connections:<\/p>\n<ul>\n<li><strong>ISP-1 (Primary Commodity WAN):<\/strong> High bandwidth (1 Gbps), lower cost, but subject to variable latency. Used for general web traffic.<\/li>\n<li><strong>ISP-2 (Secondary Dedicated WAN):<\/strong> Lower bandwidth (200 Mbps), higher cost, guaranteed low latency and strict SLA. Used for enterprise SaaS systems and partner API connectivity.<\/li>\n<\/ul>\n<p>The network team must satisfy a strict requirement: All database replication and HTTPS application traffic originating from the internal application server (<code>10.0.10.50<\/code>) toward an external cloud partner (<code>198.51.100.50<\/code>) must egress through <strong>ISP-2<\/strong>. All other general outbound traffic from the internal network (<code>10.0.10.0\/24<\/code>) must continue using <strong>ISP-1<\/strong>.<\/p>\n<p>Standard destination-based static routing cannot achieve this because both internet connections reach the same external destination IP address over default routes. Implementing a policy route allows us to override the default routing table lookup specifically for traffic originating from our application server.<\/p>\n<h2>Lab Topology<\/h2>\n<p>The following diagram illustrates the lab setup for this tutorial:<\/p>\n<pre>\n                                  +-------------------+\n                                  |   ISP-1 (Primary) |\n                             +---&gt;| Gateway:          |---&gt; General Internet\n                             |    | 192.0.2.254       |\n                             |    +-------------------+\n                             |\n                      [wan1: 192.0.2.1\/24]\n                        +-----------+\n[ Internal Subnet ]----&gt;| FortiGate |\n 10.0.10.0\/24           | Firewall  |\n (Ingress: port1)       +-----------+\n                      [wan2: 203.0.113.1\/24]\n                             |\n                             |    +-------------------+\n                             +---&gt;| ISP-2 (Secondary) |\n                                  | Gateway:          |---&gt; Cloud Partner Application\n                                  | 203.0.113.254     |     (198.51.100.50)\n                                  +-------------------+\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>The table below lists the network parameters, IP ranges, and firewall objects used in this tutorial. Modify these example values to match your specific environment.<\/p>\n<table>\n<thead>\n<tr>\n<th>Parameter \/ Object Name<\/th>\n<th>Type \/ Interface<\/th>\n<th>Value \/ IP Address<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>port1<\/code><\/td>\n<td>Hardware Interface<\/td>\n<td>10.0.10.1\/24<\/td>\n<td>Internal LAN Gateway Interface<\/td>\n<\/tr>\n<tr>\n<td><code>wan1<\/code><\/td>\n<td>Hardware Interface<\/td>\n<td>192.0.2.1\/24<\/td>\n<td>Primary ISP Egress Interface<\/td>\n<\/tr>\n<tr>\n<td><code>wan2<\/code><\/td>\n<td>Hardware Interface<\/td>\n<td>203.0.113.1\/24<\/td>\n<td>Secondary ISP Egress Interface<\/td>\n<\/tr>\n<tr>\n<td><code>ISP1_GW<\/code><\/td>\n<td>Next-Hop Router<\/td>\n<td>192.0.2.254<\/td>\n<td>Primary Gateway (ISP-1)<\/td>\n<\/tr>\n<tr>\n<td><code>ISP2_GW<\/code><\/td>\n<td>Next-Hop Router<\/td>\n<td>203.0.113.254<\/td>\n<td>Secondary Gateway (ISP-2)<\/td>\n<\/tr>\n<tr>\n<td><code>Host_AppServer<\/code><\/td>\n<td>Firewall Address Object<\/td>\n<td>10.0.10.50\/32<\/td>\n<td>Internal Application Server IP<\/td>\n<\/tr>\n<tr>\n<td><code>Ext_CloudPartner<\/code><\/td>\n<td>Firewall Address Object<\/td>\n<td>198.51.100.50\/32<\/td>\n<td>External Cloud Application IP<\/td>\n<\/tr>\n<tr>\n<td><code>LAN_Subnet<\/code><\/td>\n<td>Firewall Address Object<\/td>\n<td>10.0.10.0\/24<\/td>\n<td>Internal User Subnet<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<p>Before configuring a policy route on your FortiGate, ensure you have completed the following foundational tasks:<\/p>\n<ol>\n<li>Both physical or virtual WAN interfaces (<code>wan1<\/code> and <code>wan2<\/code>) are configured with correct IP addresses and link status is UP.<\/li>\n<li>Valid static routes exist in the main routing table for both WAN links. FortiOS policy routes require an active route in the routing table (FIB) to the destination interface to be considered valid.<\/li>\n<li>Firewall policies are created to allow traffic through BOTH egress interfaces. A policy route only steers traffic; firewall policies must explicitly permit the traffic and perform Source NAT (SNAT).<\/li>\n<\/ol>\n<h2>Step-by-Step GUI Configuration for FortiGate Policy Routes<\/h2>\n<p>Follow these steps to configure address objects, firewall policies, and the policy route in the FortiOS graphical user interface.<\/p>\n<h3>Step 1: Create Address Objects<\/h3>\n<ol>\n<li>Navigate to <strong>Policy &amp; Objects &gt; Addresses<\/strong>.<\/li>\n<li>Click <strong>Create New &gt; Address<\/strong>.<\/li>\n<li>Define the internal application server:\n<ul>\n<li><strong>Name:<\/strong> <code>Host_AppServer<\/code><\/li>\n<li><strong>Type:<\/strong> Subnet<\/li>\n<li><strong>IP\/Netmask:<\/strong> <code>10.0.10.50\/32<\/code><\/li>\n<li><strong>Interface:<\/strong> Any<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<li>Click <strong>Create New &gt; Address<\/strong> again to define the external destination:\n<ul>\n<li><strong>Name:<\/strong> <code>Ext_CloudPartner<\/code><\/li>\n<li><strong>Type:<\/strong> Subnet<\/li>\n<li><strong>IP\/Netmask:<\/strong> <code>198.51.100.50\/32<\/code><\/li>\n<li><strong>Interface:<\/strong> Any<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 2: Create Gateway Firewall Policies<\/h3>\n<p>Policy routes select the outbound interface, but the firewall engine evaluates security rules afterward. You must create firewall policies for both egress interfaces.<\/p>\n<ol>\n<li>Navigate to <strong>Policy &amp; Objects &gt; Firewall Policy<\/strong>.<\/li>\n<li>Click <strong>Create New<\/strong> to set up the default ISP-1 rule:\n<ul>\n<li><strong>Name:<\/strong> <code>Allow_LAN_to_ISP1<\/code><\/li>\n<li><strong>Incoming Interface:<\/strong> <code>port1<\/code><\/li>\n<li><strong>Outgoing Interface:<\/strong> <code>wan1<\/code><\/li>\n<li><strong>Source:<\/strong> <code>LAN_Subnet<\/code><\/li>\n<li><strong>Destination:<\/strong> <code>all<\/code><\/li>\n<li><strong>Service:<\/strong> <code>ALL<\/code><\/li>\n<li><strong>Action:<\/strong> <code>ACCEPT<\/code><\/li>\n<li><strong>NAT:<\/strong> Enabled (Use Outgoing Interface Address)<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<li>Click <strong>Create New<\/strong> to set up the dedicated ISP-2 rule:\n<ul>\n<li><strong>Name:<\/strong> <code>Allow_AppServer_to_ISP2<\/code><\/li>\n<li><strong>Incoming Interface:<\/strong> <code>port1<\/code><\/li>\n<li><strong>Outgoing Interface:<\/strong> <code>wan2<\/code><\/li>\n<li><strong>Source:<\/strong> <code>Host_AppServer<\/code><\/li>\n<li><strong>Destination:<\/strong> <code>Ext_CloudPartner<\/code><\/li>\n<li><strong>Service:<\/strong> <code>HTTPS<\/code><\/li>\n<li><strong>Action:<\/strong> <code>ACCEPT<\/code><\/li>\n<li><strong>NAT:<\/strong> Enabled (Use Outgoing Interface Address)<\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h3>Step 3: Add Policy Route<\/h3>\n<ol>\n<li>Navigate to <strong>Network &gt; Policy Routes<\/strong>.<\/li>\n<li>Click <strong>Create New<\/strong>.<\/li>\n<li>Configure the policy route settings:\n<ul>\n<li><strong>Type:<\/strong> Policy Route<\/li>\n<li><strong>Incoming interface:<\/strong> <code>port1<\/code><\/li>\n<li><strong>Source Address:<\/strong> Choose Address Building Block, select <code>Host_AppServer<\/code>.<\/li>\n<li><strong>Destination Address:<\/strong> Choose Address Building Block, select <code>Ext_CloudPartner<\/code>.<\/li>\n<li><strong>Protocol:<\/strong> <code>6<\/code> (TCP)<\/li>\n<li><strong>Incoming Port \/ Destination Port:<\/strong> Set Destination Port range from <code>443<\/code> to <code>443<\/code>.<\/li>\n<li><strong>Action:<\/strong> <code>Forward Traffic<\/code><\/li>\n<li><strong>Outgoing interface:<\/strong> <code>wan2<\/code><\/li>\n<li><strong>Gateway IP:<\/strong> <code>203.0.113.254<\/code><\/li>\n<\/ul>\n<\/li>\n<li>Click <strong>OK<\/strong>.<\/li>\n<\/ol>\n<h2>CLI Configuration<\/h2>\n<p>Engineers managing FortiGate devices often prefer the command-line interface for precision and speed. Below is the complete, validated CLI script to build this scenario.<\/p>\n<h3>Step 1: Configure Address Objects<\/h3>\n<pre><code>config firewall address\n    edit \"Host_AppServer\"\n        set subnet 10.0.10.50 255.255.255.255\n    next\n    edit \"Ext_CloudPartner\"\n        set subnet 198.51.100.50 255.255.255.255\n    next\n    edit \"LAN_Subnet\"\n        set subnet 10.0.10.0 255.255.255.0\n    next\nend<\/code><\/pre>\n<h3>Step 2: Configure Static Default Routes<\/h3>\n<p>Both gateways must exist in the routing configuration. We assign a higher administrative distance to the backup default route or keep equal distance if load distribution is planned.<\/p>\n<pre><code>config router static\n    edit 1\n        set gateway 192.0.2.254\n        set device \"wan1\"\n        set comment \"Primary Default Route\"\n    next\n    edit 2\n        set gateway 203.0.113.254\n        set device \"wan2\"\n        set distance 10\n        set comment \"Secondary Default Route\"\n    next\nend<\/code><\/pre>\n<h3>Step 3: Configure Firewall Policies<\/h3>\n<pre><code>config firewall policy\n    edit 10\n        set name \"Allow_LAN_to_ISP1\"\n        set srcintf \"port1\"\n        set dstintf \"wan1\"\n        set srcaddr \"LAN_Subnet\"\n        set dstaddr \"all\"\n        set action accept\n        set schedule \"always\"\n        set service \"ALL\"\n        set nat enable\n    next\n    edit 20\n        set name \"Allow_AppServer_to_ISP2\"\n        set srcintf \"port1\"\n        set dstintf \"wan2\"\n        set srcaddr \"Host_AppServer\"\n        set dstaddr \"Ext_CloudPartner\"\n        set action accept\n        set schedule \"always\"\n        set service \"HTTPS\"\n        set nat enable\n    next\nend<\/code><\/pre>\n<h3>Step 4: Configure Policy-Based Route<\/h3>\n<p>Now, build the exact <code>config router policy<\/code> entry to enforce traffic path selection.<\/p>\n<pre><code>config router policy\n    edit 1\n        set input-device \"port1\"\n        set srcaddr \"Host_AppServer\"\n        set dstaddr \"Ext_CloudPartner\"\n        set protocol 6\n        set start-port 443\n        set end-port 443\n        set gateway 203.0.113.254\n        set output-device \"wan2\"\n        set comments \"Route HTTPS traffic from App Server via ISP-2\"\n    next\nend<\/code><\/pre>\n<h2>How the Traffic Flows<\/h2>\n<p>Understanding FortiOS packet processing is critical for accurate engineering and rapid troubleshooting. FortiGate evaluates packets passing through the system in a deterministic sequence.<\/p>\n<ol>\n<li><strong>Ingress &amp; Stateful Session Check:<\/strong> A packet arrives on <code>port1<\/code>. FortiGate checks if this frame matches an existing active session in its state table. If it does, routing is bypassed, and the packet follows the established session paths.<\/li>\n<li><strong>Policy Route (PBR) Lookup:<\/strong> If the packet starts a new session (TCP SYN), FortiGate evaluates the active policy route table (<code>config router policy<\/code>) <em>before<\/em> searching the standard Forwarding Information Base (FIB).<\/li>\n<li><strong>PBR Match Verification:<\/strong> FortiGate compares the packet parameters against configured policy routes from top to bottom.\n<ul>\n<li>If criteria match (Source IP <code>10.0.10.50<\/code>, Destination IP <code>198.51.100.50<\/code>, Protocol 6, Port 443), FortiGate selects <code>wan2<\/code> and next-hop <code>203.0.113.254<\/code>.<\/li>\n<li>FortiGate checks if a valid active route to destination <code>198.51.100.50<\/code> exists via <code>wan2<\/code> in the main routing table. If verified, the policy route is applied.<\/li>\n<\/ul>\n<\/li>\n<li><strong>Firewall Policy Lookup:<\/strong> Once the egress interface is determined (<code>wan2<\/code>), FortiGate searches security policies matching source interface <code>port1<\/code> and destination interface <code>wan2<\/code>.\n<ul>\n<li>If policy rule 20 matches, the packet is accepted. If no security policy allows <code>port1<\/code> to <code>wan2<\/code>, the packet is dropped immediately.<\/li>\n<\/ul>\n<\/li>\n<li><strong>SNAT Processing:<\/strong> Policy 20 calls for NAT. FortiGate rewrites the source IP address from <code>10.0.10.50<\/code> to the interface address of <code>wan2<\/code> (<code>203.0.113.1<\/code>).<\/li>\n<li><strong>Egress:<\/strong> FortiGate transmits the frame out of interface <code>wan2<\/code> toward gateway <code>203.0.113.254<\/code>.<\/li>\n<\/ol>\n<h2>Verification<\/h2>\n<p>After completing the configuration, verify that your policy route active status and routing matches function correctly.<\/p>\n<h3>1. Inspect Policy Route Status via CLI<\/h3>\n<p>To inspect active Policy-Based Routing entries loaded into the kernel, run:<\/p>\n<pre><code>get router info routing-table all<\/code><\/pre>\n<p>To view policy route details specifically, execute:<\/p>\n<pre><code>diagnose firewall pbr list<\/code><\/pre>\n<p>This command outputs active PBR details, internal IDs, hit counts, incoming\/outgoing interfaces, and destination gateway definitions.<\/p>\n<h3>2. Trace Active Sessions<\/h3>\n<p>Generate application traffic from the application server toward <code>198.51.100.50:443<\/code>. Then, filter active firewall sessions on the FortiGate:<\/p>\n<pre><code>diagnose sys session filter src 10.0.10.50\ndiagnose sys session filter dst 198.51.100.50\ndiagnose sys session list<\/code><\/pre>\n<p>Look at the output lines showing <code>proto=6<\/code>, <code>outdev=wan2<\/code>, and confirm source NAT is rewriting the IP address to <code>203.0.113.1<\/code>.<\/p>\n<h2>Troubleshooting Policy Routing Issues<\/h2>\n<p>When policy routes fail to steer traffic as expected, systematic execution of diagnostic tools will identify the root cause quickly.<\/p>\n<h3>Diagnostic Workflow<\/h3>\n<p>Use the FortiGate debug flow engine to observe real-time routing decisions taken by the kernel.<\/p>\n<div class=\"caution\">\n<p><strong>CAUTION:<\/strong> Running high-volume debugs on high-throughput firewalls can elevate CPU usage. Always apply specific filters before enabling packet tracing.<\/p>\n<\/div>\n<p>Execute the following debug commands in sequence:<\/p>\n<pre><code>diagnose debug reset\ndiagnose debug flow filter saddr 10.0.10.50\ndiagnose debug flow filter daddr 198.51.100.50\ndiagnose debug flow filter port 443\ndiagnose debug flow show function-name enable\ndiagnose debug flow trace start 10\ndiagnose debug enable<\/code><\/pre>\n<p>Send test traffic from your server. The CLI output displays real-time processing logs similar to this snippet:<\/p>\n<pre><code>id=20085 trace_id=1 msg=\"allocate a new session-0004a123\"\nid=20085 trace_id=1 msg=\"find a route: flag=04000001 gw=203.0.113.254 via wan2\"\nid=20085 trace_id=1 msg=\"matched Policy Route id=1 to gateway 203.0.113.254 via wan2\"\nid=20085 trace_id=1 msg=\"allowed by Policy-20:\"<\/code><\/pre>\n<p>When testing concludes, disable debugging immediately using this cleanup command:<\/p>\n<pre><code>diagnose debug disable\ndiagnose debug flow trace stop<\/code><\/pre>\n<h3>Troubleshooting Matrix<\/h3>\n<table>\n<thead>\n<tr>\n<th>Symptom<\/th>\n<th>Likely Cause<\/th>\n<th>Resolution Check<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Traffic egresses via default WAN (<code>wan1<\/code>) instead of policy WAN (<code>wan2<\/code>).<\/td>\n<td>Policy route sequence order is incorrect, or gateway route is inactive.<\/td>\n<td>Ensure the policy route is placed above conflicting PBR entries. Verify a valid static route exists to the destination via <code>wan2<\/code>.<\/td>\n<\/tr>\n<tr>\n<td>Packet is dropped at FortiGate (<code>msg=\"Denied by forward policy\"<\/code> in flow trace).<\/td>\n<td>Missing or misconfigured firewall security policy for <code>port1<\/code> &gt; <code>wan2<\/code>.<\/td>\n<td>Create or update firewall policy allowing traffic from <code>port1<\/code> to <code>wan2<\/code> matching the required source and destination objects.<\/td>\n<\/tr>\n<tr>\n<td>Policy route matches, traffic leaves <code>wan2<\/code>, but returns are never received.<\/td>\n<td>Source NAT is disabled, or upstream gateway drops unroutable internal RFC1918 IPs.<\/td>\n<td>Enable NAT on the outbound firewall policy targeting <code>wan2<\/code>, or use an explicit IP Pool assigned by ISP-2.<\/td>\n<\/tr>\n<tr>\n<td>Existing connections continue using the old interface after adding a policy route.<\/td>\n<td>FortiGate maintains existing session table entries for established streams.<\/td>\n<td>Clear specific existing sessions using <code>diagnose sys session clear<\/code> or wait for active TCP connections to close natively.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Common Mistakes<\/h2>\n<ul>\n<li><strong>Forgetting Firewall Security Policies:<\/strong> A policy route determines egress interface, but does not allow traffic. If no security policy permits traffic from source interface to target egress interface, traffic is dropped.<\/li>\n<li><strong>Omitting Main Routing Table Routes:<\/strong> FortiOS requires a matching active route entry in the standard routing table for policy routes to remain active. If the egress interface has no valid route to the destination in the main routing table, FortiGate bypasses the policy route.<\/li>\n<li><strong>Incorrect Rule Order:<\/strong> FortiGate processes policy routes top-down. If a broad rule (e.g., matching source <code>10.0.10.0\/24<\/code> to destination <code>all<\/code>) sits higher in the list, specific host rules below it will never match.<\/li>\n<li><strong>Neglecting SNAT Requirements:<\/strong> ISP routers drop packets carrying internal RFC 1918 addresses. Always verify that outbound security policies perform Source NAT to the exit WAN interface IP or pool.<\/li>\n<\/ul>\n<h2>Production Considerations<\/h2>\n<p>Before implementing policy routes in mission-critical corporate environments, evaluate these strategic considerations:<\/p>\n<h3>Policy Routes vs. SD-WAN Rules<\/h3>\n<p>While policy routes remain reliable for static routing overrides, FortiOS SD-WAN offers modern alternatives. SD-WAN rules integrate dynamic performance SLA measurements (jitter, latency, packet loss) across multiple ISPs. Consider upgrading policy routes to SD-WAN rules if you require dynamic automatic failover based on WAN quality degradation rather than hard physical link failures.<\/p>\n<h3>Link Monitoring &amp; Failover<\/h3>\n<p>Standard policy routes remain active as long as the underlying egress interface status stays UP. If ISP-2 suffers an upstream outage while its physical port remains connected, standard policy routes will continue forwarding traffic into the black hole. Pair static routes with <code>config system link-monitor<\/code> or migrate to SD-WAN to automatically invalidate routes when upstream health checks fail.<\/p>\n<h3>Session Management<\/h3>\n<p>Policy routes apply to new session establishment. Modifying policy routes while production applications run will not instantly alter active TCP connections already recorded in the session state table. Plan maintenance windows accordingly when adjusting traffic paths for persistent database or VoIP connections.<\/p>\n<h2>Related FortiGate Guides<\/h2>\n<ul>\n<li><a href=\"\/tutorials\/fortinet\/fortigate-sd-wan-configuration-for-dual-isp-failover-and-load-balancin\/\">FortiGate SD-WAN dual ISP failover<\/a><\/li>\n<li><a href=\"\/tutorials\/fortinet\/fortigate-session-troubleshooting-with-flow-debug-sessions-and-logs\/\">FortiGate session troubleshooting<\/a><\/li>\n<li><a href=\"\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/\">FortiGate HA and failover testing<\/a><\/li>\n<\/ul>\n<h2>Summary<\/h2>\n<p>Mastering <strong>FortiGate policy route configuration<\/strong> allows administrators to control multi-WAN traffic patterns precisely. By bypassing standard destination-only routing lookups, you can direct application-critical traffic over performant dedicated links while offloading background traffic to secondary circuits.<\/p>\n<p>Always align your policy routes with proper firewall security rules, active static routes, and correct SNAT mechanisms. When traffic behavior deviates from design expectations, leverage <code>diagnose debug flow<\/code> commands to isolate routing and security decisions within FortiOS.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Learn FortiGate policy route configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.<\/p>","protected":false},"author":2,"featured_media":1377,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[4],"tags":[137,29,41,1156,44,43,35],"class_list":["post-1378","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fortinet","tag-advanced","tag-firewall-tutorial","tag-fortigate","tag-fortigate-policy-route-configuration","tag-fortinet","tag-fortios","tag-routing"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>FortiGate Policy Route Configuration with Dual ISP...<\/title>\n<meta name=\"description\" content=\"Learn FortiGate policy route configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FortiGate Policy Route Configuration with Dual ISP Real-Life Examples\" \/>\n<meta property=\"og:description\" content=\"Learn FortiGate policy route configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-09T20:21:16+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-13T23:01:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples-featured.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"10 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"FortiGate Policy Route Configuration with Dual ISP Real-Life Examples\",\"datePublished\":\"2026-09-09T20:21:16+00:00\",\"dateModified\":\"2026-09-13T23:01:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/\"},\"wordCount\":1713,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples-featured.jpg\",\"keywords\":[\"Advanced\",\"Firewall Tutorial\",\"FortiGate\",\"FortiGate policy route configuration\",\"Fortinet\",\"FortiOS\",\"Routing\"],\"articleSection\":[\"FortiGate\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/\",\"name\":\"FortiGate Policy Route Configuration with Dual ISP...\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples-featured.jpg\",\"datePublished\":\"2026-09-09T20:21:16+00:00\",\"dateModified\":\"2026-09-13T23:01:05+00:00\",\"description\":\"Learn FortiGate policy route configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples-featured.jpg\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples-featured.jpg\",\"width\":1200,\"height\":630,\"caption\":\"FortiGate Policy Route Configuration with Dual ISP Real-Life Examples\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FortiGate Policy Route Configuration with Dual ISP Real-Life Examples\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"FortiGate Policy Route Configuration with Dual ISP...","description":"Learn FortiGate policy route configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/","og_locale":"en_US","og_type":"article","og_title":"FortiGate Policy Route Configuration with Dual ISP Real-Life Examples","og_description":"Learn FortiGate policy route configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/","og_site_name":"NetworkFix","article_published_time":"2026-09-09T20:21:16+00:00","article_modified_time":"2026-09-13T23:01:05+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples-featured.jpg","type":"image\/jpeg"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"10 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"FortiGate Policy Route Configuration with Dual ISP Real-Life Examples","datePublished":"2026-09-09T20:21:16+00:00","dateModified":"2026-09-13T23:01:05+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/"},"wordCount":1713,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples-featured.jpg","keywords":["Advanced","Firewall Tutorial","FortiGate","FortiGate policy route configuration","Fortinet","FortiOS","Routing"],"articleSection":["FortiGate"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/","url":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/","name":"FortiGate Policy Route Configuration with Dual ISP...","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples-featured.jpg","datePublished":"2026-09-09T20:21:16+00:00","dateModified":"2026-09-13T23:01:05+00:00","description":"Learn FortiGate policy route configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples-featured.jpg","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples-featured.jpg","width":1200,"height":630,"caption":"FortiGate Policy Route Configuration with Dual ISP Real-Life Examples"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-policy-route-configuration-with-dual-isp-real-life-examples\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"FortiGate Policy Route Configuration with Dual ISP Real-Life Examples"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1378","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=1378"}],"version-history":[{"count":1,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1378\/revisions"}],"predecessor-version":[{"id":1556,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1378\/revisions\/1556"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/1377"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=1378"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=1378"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=1378"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}