Skip to main content
CITS
New Member
February 13, 2019
Solved

Dual WAN, Dual LAN

  • February 13, 2019
  • 1 reply
  • 3720 views

Hi Everyone, 

 

I have a 200E deployed and we have two separate static ISP connections coming in from the same provider, utilizing the same GW.

 

I have two LANS set up, with identical static routes

[ul]
  • 0.0.0.0/0 - GW - WAN1
  • 0.0.0.0/0 - GW - WAN2[/ul]

    And IPV4 policies

    [ul]
  • Lan1 - Wan1 - all -all -always -all -accept -NAT - Use Outgoing Interface
  • Lan2 - Wan2 - all -all -always -all -accept -NAT - Use Outgoing Interface[/ul]

     

    Issue is that  I can only get to the internet on one of LAN1-WAN1 network, the secondary LAN wont connect/ping to the internet.

    • Best answer by bmorris

      I would suspect that only one of the default routes is entered into the routing table that is why lan1-wan1 works. Likely what is happening is that the firewall wants to forward traffic from lan2 out of wan1 but there is no policy to allow this so it is dropped. You will need to configure either of these two features:

       

      - SD-WAN

      - Policy routing

       

      With SD-WAN you can put both WAN interfaces into a logical 'SD-WAN' interface then create a rule that says anyone coming from lan2 only goes out via wan2.

       

      With policy routing you can create a rule that forces all lan2 traffic to go out of wan2 instead of wan1. You will need to have both default routes in the static routing table for this, but one will need a higher metric.

       

      1 reply

      bmorris
      bmorrisAnswer
      New Member
      February 13, 2019

      I would suspect that only one of the default routes is entered into the routing table that is why lan1-wan1 works. Likely what is happening is that the firewall wants to forward traffic from lan2 out of wan1 but there is no policy to allow this so it is dropped. You will need to configure either of these two features:

       

      - SD-WAN

      - Policy routing

       

      With SD-WAN you can put both WAN interfaces into a logical 'SD-WAN' interface then create a rule that says anyone coming from lan2 only goes out via wan2.

       

      With policy routing you can create a rule that forces all lan2 traffic to go out of wan2 instead of wan1. You will need to have both default routes in the static routing table for this, but one will need a higher metric.

       

      Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!