Technical Tip: SD-WAN member Gateway IPs should not overlap with Firewall IP pool ranges
| Description | This article explains an issue where FortiGate does not prevent SD-WAN member gateway IP addresses from overlapping with the IP ranges defined in firewall IP pools. |
| Scope | FortiGate v7.6.3. |
| Solution | When an SD-WAN member’s gateway overlaps with the IP range of a firewall IP pool, installing routes into the Kernel can cause unexpected behavior, potentially resulting in connectivity issues. Sample config:
config system interface config sys sdwan Starting from v8.0.0(scheduled to be released in February 2026), the error 'Gateway IP can not overlap with firewall ippool's IP range.' will be reported by FortiGate when an SD-WAN member’s gateway IP overlaps with the IP range of a firewall IP pool.
These timelines for firmware release are estimates and may be subject to change. config sys sdwan |