← Back to knowledge base
medium

SD-WAN rules using route tags stop matching after an SD-WAN reset

Confirmed 9/17/2026

Problem

On FortiGate, running an SD-WAN reset clears the application-control Internet Service cache and the route-tag address cache. In FortiOS 7.2 or earlier, this can leave SD-WAN rules that use `set route-tag` without destination addresses, preventing those rules from matching traffic.

Symptoms

Before the reset, the route-tag rule contains its learned address. In this example, route tag 10 maps 8.8.8.8 to SD-WAN member 3 on port1: ``` FGT-7-2 # show system sdwan config system sdwan set status enable config zone edit "virtual-wan-link" next end config members edit 1 set interface "port8" set gateway 10.5.255.254 next edit 2 set interface "port9" set gateway 10.5.191.254 next edit 3 set interface "port1" set gateway 10.134.19.165 set priority 100 next end [...] config service edit 1 set name "Tag-10" set route-tag 10 set priority-members 3 next edit 2 set name "all-to-internet" set dst "all" set priority-members 2 1 next end end ``` ``` FGT-7-2 # diagnose sys sdwan service Service(1): Address Mode(IPV4) flags=0x200 use-shortcut-sla Tie break: cfg Gen(1), TOS(0x0/0x0), Protocol(0: 1->65535), Mode(manual) Members(1): 1: Seq_num(3 port1), alive, selected Route tag address(1): 8.8.8.8-8.8.8.8 Service(2): Address Mode(IPV4) flags=0x200 use-shortcut-sla Tie break: cfg Gen(1), TOS(0x0/0x0), Protocol(0: 1->65535), Mode(manual) Members(2): 1: Seq_num(2 port9), alive, selected 2: Seq_num(1 port8), alive, selected Dst address(1): 0.0.0.0-255.255.255.255 ``` After the following reset, service 1 is disabled because it has no destination: ``` FGT-7-2 # diagnose sys sdwan reset All SD-WAN application ctrl internet service cache and route-tag address cache will be clean out. Do you want to continue? (y/n)y ``` ``` FGT-7-2 # diagnose sys sdwan service Service(1): Address Mode(IPV4) flags=0x200 use-shortcut-sla Tie break: cfg Gen(1), TOS(0x0/0x0), Protocol(0: 1->65535), Mode(manual) Service disabled caused by no destination. Members(1): 1: Seq_num(3 port1), alive, selected Service(2): Address Mode(IPV4) flags=0x200 use-shortcut-sla Tie break: cfg Gen(1), TOS(0x0/0x0), Protocol(0: 1->65535), Mode(manual) Members(2): 1: Seq_num(2 port9), alive, selected 2: Seq_num(1 port8), alive, selected Dst address(1): 0.0.0.0-255.255.255.255 ```

Environment

FortiGate using BGP-learned route tags in SD-WAN rules. The example has three SD-WAN members: port8 through gateway 10.5.255.254, port9 through gateway 10.5.191.254, and port1 through gateway 10.134.19.165 with priority 100. Route tag 10 selects member 3, port1, for 8.8.8.8. All remaining traffic uses members 2 and 1, port9 and port8.

FortiOS version

FortiOS 7.2 or earlier. This behavior does not apply from FortiOS 7.4 because route-tag handling was redesigned to use route-tag address objects, and an SD-WAN reset no longer removes route-tag information.

Root Cause

Route tags are learned through BGP rather than by the SD-WAN daemon. The `diagnose sys sdwan reset` command removes the route-tag address cache. On FortiOS 7.2 or earlier, the affected SD-WAN rule then has no destination and remains disabled until BGP repopulates the route-tag information.

Solution

  1. Confirm that the route-tag SD-WAN service reports Service disabled caused by no destination.:
diagnose sys sdwan service
  1. Restart all BGP sessions so that FortiGate relearns the route tags and restores the SD-WAN route-tag address cache:
execute router clear bgp all
  1. Be aware that this action affects traffic. All BGP connections are torn down and must be re-established.

Verification

Run the SD-WAN service diagnostic again:

diagnose sys sdwan service

In the example, service 1 becomes active again and 8.8.8.8 is restored as the address associated with route tag 10:

Service(1): Address Mode(IPV4) flags=0x200 use-shortcut-sla
Tie break: cfg
Gen(2), TOS(0x0/0x0), Protocol(0: 1->65535), Mode(manual)
Members(1):
    1: Seq_num(3 port1), alive, selected
Route tag address(1):
8.8.8.8-8.8.8.8
Service(2): Address Mode(IPV4) flags=0x200 use-shortcut-sla
Tie break: cfg
Gen(1), TOS(0x0/0x0), Protocol(0: 1->65535), Mode(manual)
Members(2):
    1: Seq_num(2 port9), alive, selected
    2: Seq_num(1 port8), alive, selected
Dst address(1):
        0.0.0.0-255.255.255.255

Tags

No tags yet.

Community rating

— / 5 (0)

Discussion (0)

    No comments yet.