Skip to main content
jgauthier
New Member
December 5, 2018
Question

Dual WAN Configuration question

  • December 5, 2018
  • 4 replies
  • 4999 views

Afternoon all,

Here is what I want to achieve : I want to use wan1 for my remote branch user's network (internet access and establish VPN to HeadQuarters) I wan to use wan2 for a guest network internet access but I'd also like to use it as a redundant interface to wan1 (with all above's functionnality)

Is this even achievable ?

Any help would be appreciated

Thanks

JF

    4 replies

    jgauthier
    jgauthierAuthor
    New Member
    December 5, 2018

    Forgot to mention that both wan connection providers are dynamic (dhcp -- pppoe)

    :)

    lobstercreed
    New Member
    December 5, 2018

    Yes, this is a very common configuration.  I would point you to this cookbook recipe for some step by step on the basics: https://cookbook.fortinet.com/redundant-internet-basic-failover-56/  Apply this as if your branch users were the only network that you cared about.

    Note: you can use a Zone to simplify the configuration a bit by adding both WAN interfaces to an "Internet" zone.

    https://cookbook.fortinet.com/using-zones-to-simplify-firewall-policies-56/

     

    Then you would additionally need to set up a firewall policy to allow traffic from the guest network to the Internet, and add some policy routing to make sure the guest network could only go out the wan2 interface (under Network -> Policy Routes).

    jgauthier
    jgauthierAuthor
    New Member
    December 5, 2018

    Thanks for the reply lobstercreed... this works perfectly IF my WAN interfaces are static IPs...

    This is my issue actually... what if both those links are dynamic (one PPPoE and one DHCP in my case) ?

     

    JF

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!