problems after upgrade to 12.4
I upgraded a M300 (with 2 external interfaces) to new 12.4B592447 and realized some connection issues. After some research it seems that the sd-wan-based policies block these connections.
...for example we have the following rules since 12.3:
HTTP_from_dmz2extern -> sd-wan based routing: only external2 (=normal DSL)
SMTP_from_extern2dmz -> sd-wan based routing: only external1 (=leased line)
SSH_from_extern2IP (static) -> sd-wan based routing: only external1
with this rules we want to prefer dedicated lines because of performance reasons or because some IP´s are only reachable with the leased line. But this constellation doesn´t work anymore, it "drops" the traffic (traffic monitor still shows passing traffic in green).
When I deactivate the sd-wan based routing it works!?
Any explanations or ideas are welcome...