De-configuring Dual WAN Load Balancing advice
Hello,
I've been running dual wan connections using ECMP Weighted Load Balance on my FWF80CM (v4 MR3 Patch 15) for a couple of years now. The solution has worked out pretty well but now I want to change this design to a more manual setup to improve control over how traffic flows through the device.
My goals:
WAN2 - Primary Gateway
WAN1 - Failover Gateway
Needs:
I will still need to Policy route some specific traffic out WAN1
I will still need to access VIPs setup on WAN1 externally
I will still need to access HTTPS admin on WAN1 externally
To start off I assumed that I could just change ECMP back to Source IP (default) and then give WAN1 administrative distance higher than WAN2. Both WAN1 and WAN2 have static routes with the same distance currently. When I did this working remotely over HTTPS on WAN1 as soon as I applied the Admin Distance on WAN1 I lost my remote connection and found that I was also unable to access HTTPS admin on WAN2. In addition when I arrived at the office HTTP/HTTPS traffic was not working. I could ping external addresses (I think) but DNS wouldn't resolve. After changing the Distance back to 0 on both interfaces and a reboot of the fortigate HTTP/HTTPS started to flow again.
I have an internal DNS server and do not use the fortigate. Can anyone tell me what might have happened. Do I need to clear the routing table or cache after changing these settings? Should I be using Priority instead of Distance? How did this affect my inbound HTTPS admin session? How does this affect inbound external traffic?
I don't know a whole lot about routing aside from what I've read in the fortigate manual and here in the forums so be gentle.
Thanks
