Skip to main content
rvdlee
New Member
March 10, 2017
Solved

External ICMP ping on secondary passive WAN interface

  • March 10, 2017
  • 1 reply
  • 7833 views

We have a Fortigate 100D firewall (Fortios 5.2.x) with Dual WAN (WAN1 and WAN2 interfaces) connectivity to 2 different ISP’s. It is acting as active/passive. WAN1 is the primary WAN link (distance 10) WAN2 is our failover link (distance 20)

All is working well but we want to monitor our WAN2 link with third-party monitoring software (Paessler PRTG) Because WAN2 is passive, ICMP ping doesn’t work. This would be the simplest method for proactively monitoring the WAN2 link with other monitoring software. I want to know if there are other methods before considering FortiAnalyzer.

 

Is it possible to enable ICMP ping to a passive WAN2 link? Are there other methods to achieve proactive alerting (e.g. e-mail, snmp) when a passive WAN2 interface fails?

 

What I’ve learned so far:

[ul]
  • I’ve been using dead gateway detection/link monitor. It writes a message to the Fortigate event log when an event happens, but I can’t extract this specific log alert with SNMP or receive an alert with alert e-mail. So I have to manually check the Fortigate log
  • SNMP events are limited to specific SNMP events categories, same goes for Alert e-mail. I can’t find options for link monitor events.[/ul]
    • Best answer by ede_pfau

      hi,

       

      just some thoughts:

      - for a WAN interface you need a default route. Use 2 default routes with same distance but higher priority on the backup WAN. ("priority" in FOS means "cost".) This way, both routes are active in the Routing monitor and should enable reply traffic.

      That is, if a passive cluster member answers to incoming traffic at all. This might well not be the case!

       

      - regarding SNMP

      how do you know that the slave unit logs an event in case it's WAN link goes down? Do you access the slave via it's mgmt interface? If so, and this is preferable, it could be possible to enable SNMP on that mgmt interface and to receive a trap. (I know, a lot of "if"s).

      1 reply

      ede_pfau
      SuperUser
      ede_pfauAnswer
      SuperUser
      March 10, 2017

      hi,

       

      just some thoughts:

      - for a WAN interface you need a default route. Use 2 default routes with same distance but higher priority on the backup WAN. ("priority" in FOS means "cost".) This way, both routes are active in the Routing monitor and should enable reply traffic.

      That is, if a passive cluster member answers to incoming traffic at all. This might well not be the case!

       

      - regarding SNMP

      how do you know that the slave unit logs an event in case it's WAN link goes down? Do you access the slave via it's mgmt interface? If so, and this is preferable, it could be possible to enable SNMP on that mgmt interface and to receive a trap. (I know, a lot of "if"s).

      Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
      Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!