Skip to main content
DamianLozano
New Member
December 2, 2019
Question

Another Load Balance for some IPs

  • December 2, 2019
  • 8 replies
  • 5617 views

Hello,

 

I have this issue not so common, so I will explain first the scenario:

- It is a Fortigate 100E with firmware version 5.6.6

- We have 2 different ISP connected to WAN1 and WAN2

- There is a kind of load balance by content, just with policy routes

- SD-Wan is not configured

- There are rules for WAN1 and rules for WAN2

- There are static routes and policy routes for WAN1 and WAN2

 

Now, we need to add another 2 ISPs in different interfaces (example: Port2 and Port3)

We need that everyone, like now, use the current settings (Without any change at all)

But we need to make a load balance between Port2 and Port3 just for some IPs (Just some IPs to go out through Port2 or Port3)

If I create a SD-Wan, I have the following issues:

- I can not create a static route because it is not allowed to create static routes for SD-Wan and not SD-Wan interfaces

- I can not create a policy route because it does not allow me to select the SD-Wan as the destination interface.

 

I could add another device to make the load balance but it is preferred to make it work with the current hardware.

 

Any Idea?

Regards,

Damián

 

    8 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    December 2, 2019

    If you are not balancing multiple interfaces pseudo randomly pointing default routes to all of them and instead setting some specific destination groups to go specific interfaces, that's regularly not called as load-balancing. It's just specific routing toward multiple internet interfaces. You can keep doing it in the same way regardless the number of interfaces.

    But even with SD-WAN, you can do the same with default routes going to all member interfaces. Despite your statement, you can set specific (static) routes toward one of SD-WAN member interfaces if you really want. But you can limit the member interfaces, like specifying only one, in the SD-WAN rule (GUI, in CLI it's called "config service" under "config sys virtual-wan-link") to limit where to go for specific destinations, sources, protocol, etc. just like policy routes, while all other traffic can be "load-balanced".

    As a matter of fact an FTNT SE called those rules as "policy routes" when he explained SD-WAN in a tech refresher seminar. 

    The hardest part is to remove all references for the member interfaces in the current config to form SD-WAN interface. It's almost equivalent to configure from scratch.

     

    DamianLozano
    New Member
    December 2, 2019

    I think I got it

    This sould be everything through 1 SD-Wan with multiple WANs using SD-WAN rules, or through different interfaces using policy routes or static routes + firewall policies.

     

    Thanks a lot

    Toshi_Esumi
    SuperUser
    SuperUser
    December 2, 2019

    By the way, it's possible to go hybrid as well; some members in SD-WAN and others independent. 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!