Skip to main content
Maerre
Explorer III
October 24, 2025
Question

Dual WAN SD-WAN configuration with service exposure on both links

  • October 24, 2025
  • 3 replies
  • 410 views

Hi,

I have a customer who currently uses two WAN connections: a primary one (Swisscom) and a secondary one (Horizon).
Some services are also exposed only on the primary WAN.
They asked if it’s possible to combine the two connections so that, in case the primary wan becomes saturated, part of the new traffic is automatically redirected to the secondary wan.
Additionally, they would like to expose services simultaneously on both WANs.

From what I understand, the only way to address the first issue is to configure an SD-WAN, adding both WANs to the Virtual Link Zone, including this zone in all policies and static routes, and then creating an SLA monitor.

As for the second point, how could that be handled?
Would it be feasible to create a virtual VIP address?

Thanks,
Cheers

3 replies

funkylicious
SuperUser
SuperUser
October 24, 2025

hi,

SD-WAN controls the egress/outbound traffic, not the ingress/inbound traffic.

they should expose the services via both public IP's on the FGT/SDWAN and create a redundancy logic at the DNS level with ttl or something similar

"jack of all trades, master of none"
Maerre
MaerreAuthor
Explorer III
October 24, 2025

Hi @funkylicious 
you mean create a redundancy logic at DNS level on FGT or on their DNS?

funkylicious
SuperUser
SuperUser
October 24, 2025

the public dns zone which resolves the hostname to ip, not locally on FGT.

"jack of all trades, master of none"
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!