Our CI/CD pipelines are failing because FortiSASE is inspecting traffic to our self-hosted runners. Large artifact uploads/downloads time out, and some package manager connections are flaky.
Need a bypass rule. Our setup:
- Runners are on a dedicated subnet: `10.10.20.0/24`
- They reach out to GitHub.com, internal artifact repos, and Docker registries.
Tried creating a security policy with deep inspection disabled, but traffic is still being funneled through the SASE tunnel. Do I need to:
1. Create a split tunnel rule specifically for the runner subnet?
2. Use SD-WAN rules to direct that traffic out a local gateway instead?
3. Something in the FortiClient EMS profile?
Looking for the specific config stanza. Our FortiGate version is 7.2.5.
cg
YAML all the things.