Skip to main content
kaman
Staff
Staff
February 3, 2025

Technical Tip: Configuring Additional Default Static Routes for non-SD-WAN Members when an SD-WAN Zone is already defined

  • February 3, 2025
  • 0 replies
  • 1000 views
Description

 

This article describes the challenges of adding a new WAN ISP (Non-SD-WAN member) to the default static route when an SD-WAN Zone is already set up.

 

Scope

 

FortiGate.

 

Solution

 

An SD-WAN zone has been set up already, with WAN1 and WAN2 added as members, and a default static route created for the SD-WAN configuration.

The error in the image below arises when adding the new WAN interface Port6 to the default static route.

sdwan-new1.png


By design, the default route cannot simultaneously be applied to SD-WAN and non-SD-WAN members.

For example, if WAN1 and WAN2 are used for the 0.0.0.0/0 route via SD-WAN, the same default route cannot be configured simultaneously through PortX.

The proper way is for the PortX to be a member of the SD-WAN and steer/route the traffic via SD-WAN-specific rules/services
Redundant Internet with SD-WAN.

Note:

In newer FortiOS releases, a new SD-WAN zone can be formed with Port6 as a member, allowing its addition to the static route configuration.


sdwan-two-static.png

 

In case there are dedicated default routes with dedicated interfaces then it is possible to add any number of default routes as mentioned below.

 

Both port1 and port2 are part of the SD-WAN zone.

 

Screenshot 2025-03-05 134809.png

 

Note: 

This regularly happens when a customer needs to connect a third link ISP or more links, like network diagram below: 

 

sd1.jpg

 

The SD-WAN zone has two port members belongs it and when the requirements need using the default route with different administrative distance. For the newest links for adding, is not possibly create another default route because is using on the SD WAN previously created and this error could be happening many times. 

 

sd4.jpg

 

sd3.jpg

 

Therefore, to solve this and to use the default route with different administrative distance or priority for the newest links is necessary create a new SD WAN zone and this prevent the misconfiguration for another SD WAN zones previously created. 

 

sd4e4.jpg

 

With this technique it is possible using again the default route for newest SD WAN zones applying different AD or priority depending on criteria. 

 

sd5.jpg

 

sd6.jpg

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.