Existing Fortigate dual wan setup, trying to introduce SDWAN
We have an existing Fortigate 7.4.11 firewall configuration with 100+ firewall policies and 10 VPN, IPSec connections and 2 WAN connections.
We are wanting to now configure SDWAN to handle the 2 WAN Connections. Has anyone retrospectively added SDWAN to your existing config?
We are looking for options.
Current options seem like
1. configure SDWAN and remove all references to the WAN interfaces (ie assigning those references to some other interface), then building SDWAN and reassigning to the zones.
Pros: point and click
Cons: take the network down for a bit while this configuration is being done and then troubleshoot issues
2. dump the config, and integrate the changes, then try to import that new config into the fortigate
Pros: seems quick, little downtime
cons: seems like it will fail.
3. script the changes and dump those into the CLE
Pros: seems quick, prone to errors
cons: troubleshooting after it fails
4. Building another SDWAN zone with a 3rd wan connection
Pros: move policies one at a time, test along the way
cons: not sure Fortigate will allow this
Any recommendations?
Thanks