By default, IKE and IPSec traffic originating
at the firewall egresses an interface that the ECMP load-balancing
method determines. Select Strict Source Path to
ensure that IKE and IPSec traffic originating at the firewall always
egresses the physical interface to which the source IP address of
the IPSec tunnel belongs. Enable Strict Source Path when the firewall
has more than one ISP providing equal-cost paths to the same destination.
The ISPs typically perform a Reverse Path Forwarding (RPF) check
(or a different check to prevent IP address spoofing) to confirm
that the traffic is egressing the same interface on which it arrived.
Because ECMP by default chooses an egress interface based on the
configured ECMP method (instead of choosing the source interface as
the egress interface), that will not be what the ISP expects and
the ISP can block legitimate return traffic. In this use case, enable Strict Source
Path so that the firewall uses the egress interface
that is the interface to which the source IP address of the IPSec
tunnel belongs. |