Question
Dual WAN config with health monitor triggered failover Policy Route question
Hi i have a FGT60D (5.4) with two WAN connections and configured a health monitor for wan1 if multiple servers are not reachable. if the health monitor takes wan1 down, wan2 starts working through the second default route with the higher distance configured. so far, this works like a charm. what i want to accomplish now is: - at least make the firewall reachable through wan2 from the outside at all time for ping and maybe https/ssh management (trusted hosts only) - if possible, also make various virtual ips via wan2 accessible all the time from the outside. i realize that this is going to be an issue because the packets wont find their right way back as long as wan1 and its default route is active. is there a way to accomplish my goals with policy routes? everything i have tried didnt work unfortunately. one way would be to put wan2 in a seperate vdom but i want to avoid going through a seperate virtual firewall instance with all the traffic and creating all those firewall policies twice, if possible. thanks for any advice! regards
