Asymmetric Routing on Different Interfaces on Same Zone
Hi all,
I'm an experienced network guy with 28 years of experience, but it's all Cisco. I'm new to Fortinet.
Here's my question: I'm working on a design for a customer with multiple satellite offices that connect back to two datacenters (primary and DR). They are all interconnected with two layer-2 ELAN WAN meshes. I want to centralize all of my routing onto the Fortigate firewalls at each location. But because the WAN links are from two separate vendors each Fortigate is going to have two physical handoffs, one to each vendor's network.
My plan is to create a WAN zone on each Fortigate and then put both physical interfaces in that same zone. (I don't need any filtering/firewalling between those interfaces.) I'm trying to find out if I am going to run into any asymmetric routing issues. The WAN circuits will be load balanced so I can't promise that packets from a particular session that go out on one vendor's circuit won't return on the other vendor's circuit. I could see this breaking stateful firewalling since the return packets will be on a different physical interface. But I could also see it working because the session's return packets will still be in the same zone.
Does anyone know if I'll run into issues here? In sum I'm looking to find out if the session based stateful firewalling references the physical interface like an ASA would, or whether it's by zone and doesn't care about the physical interface.
Thanks,
Ben
