Skip to main content
ThePro
New Member
February 27, 2017
Question

2 Wans - Splitting traffic based on IP or MAC

  • February 27, 2017
  • 8 replies
  • 11892 views

I have a Fortigate 60D. WAN1 has a static IP and WAN2 does not. I want to leave WAN1 as primary for S2S VPNs and WAN2 so some devices go through it (by either the device IP or MAC address). Redundancy would be nice, but not necessary for what I'm trying to accomplish. Is this possible?

    8 replies

    support12
    New Member
    February 27, 2017

    Yes

    Si 2 rutas estaticas tipo default misma metrica y prioridad debe ser distinta para definir primario y secundario 0.0.0.0/0  apuntando a cada isp.

    un link monitor o pin server apuntando a 1 ip por cada isp para monitorear estado up del isp

    1 policy route que diga todo lo que  venga por esta interface  diagomos como source si su red interna es

      192.168.1.0/24  pues la mitad seria 192.168.1.0/25  y como destino usas el isp que desees.

    2 otro policy route si lo deseas por puerto o servicios

     

    Tambien leer en fortinet este tema lo mas que tiene son  ejemplos

    tanr
    New Member
    February 27, 2017

    I would recommend a little different setup than nustream.  

    Pues, creo que mi recomendación es un poco diferente, pero no entendí todo de su explanación.

     

    Though for your situation you do want two static default routes, both default static routes should have the same distance, but one (say WAN1) should have a smaller number for priority (lower value = higher priority) than the other.  This will mean that both routes stay in the routing table but without some other intervention everything will go through the higher priority route.

     

    Then, create one or more policy routes that can be based off incoming interface, protocol, subnet, etc. to route the subnets, interfaces, or devices you want to the WAN2 interface.  Don't specify a gateway address (use 0.0.0.0)  and the policy route will then cause all these to use the second, WAN2, default static route.

     

    Note that this solution, as is, will let all your traffic use WAN2 if WAN1 is down.

     

    You can create some problems with this if you  aren't careful and allow communications to come in through WAN1 that are responded to through WAN2.  Once you narrow down your scenario and what solution you would like to use you might want to post it here to see if anybody else can point out possible problems before you go live with it.

     

    Besides the base documentation (http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-advanced-routing-54/Routing_Advanced_Static/adv_static_routing.htm#) here are some other articles about this I found useful

    (note that ECMP and other details have changed somewhat in 5.4):

    http://kb.fortinet.com/kb/viewContent.do?externalId=FD32103

    http://docs.fortinet.com/uploaded/files/1709/Multi-path_Routing_Basics.pdf

    http://kb.fortinet.com/kb/documentLink.do?externalID=FD36462

    http://kb.fortinet.com/kb/documentLink.do?popup=true&externalID=FD30907

    http://kb.fortinet.com/kb/documentLink.do?externalID=FD31844

     

    ThePro
    TheProAuthor
    New Member
    March 1, 2017

    tanr wrote:

    You can create some problems with this if you  aren't careful and allow communications to come in through WAN1 that are responded to through WAN2.  Once you narrow down your scenario and what solution you would like to use you might want to post it here to see if anybody else can point out possible problems before you go live with it.

    Let me explain a bit more in case I wasn't clear.

     

    WAN1 has a static/public IP - I VPNs setup using this interface

    WAN2 doesn't (DCHP)

     

    Normally everything goes through WAN1. If WAN1 goes down evething goes through WAN2.

     

    What I want is to allow some specific devices on the network to ALWAYS use WAN2 (lets say everything goes through WAN1, but the device with the IP 10.0.0.150 will always go through WAN2). I read on a post from 2015 that it should be possible via a Policy Route ...

     

    https wrote:

    Create a policy based route by clicking on System > Router > Policy Route > Create New>   Source Interface - Internal; Source Address :Test PC IP Destination Address - ANY(0.0.0.0/0.0.0.0); Outgoing Interface: Wan2; Gateway: 0.0.0.0;

     

    The problem is that in that part where it says Source Address :Test PC IP if I type the IP of the device (10.0.0.50) I get this error Invalid IP range. So it doesn't save the changes. If I type 10.0.0.150/255.255.255.0 it accepts the changes, but when I look a the routing table instead of having 10.0.0.150/255.255.255.0 on the source address I get this 10.0.0.0/255.255.255.0. So I assume that would mean the Policy Route will apply to the whole Subnet instead of a specific device.

     

    Any ideas?

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!