Skip to main content
harsh_mittal
Explorer
May 23, 2025
Question

Fortigate Firewall 101F Interface config

  • May 23, 2025
  • 2 replies
  • 865 views

I have created the BDI interfaces on the Cisco SD-WAN routers with VRRP. Fortigate firewalls are working in active passive mode. We have connections to both routers from each firewall. Please suggest the config to follow here on FortiGate so that in case the link to SD-WAN router 1 goes down from FortiGate firewall 1, traffic should go out from SD-WAN router 2 from FortiGate firewall 1 link. Please suggest other options also 

 

dijix1990_0-1747971171768.png

 

 
 

 

 

2 replies

harsh_mittal
Explorer
May 26, 2025

Thanks for sharing the documentation.

In the snip, we connect to both routers from the active and passive firewall on the same VLAN. meaning, Physical interfaces on firewalls connecting to the router are in the same network. Is there any way, i can add fw ports in same vlan and so both ports become part of same network.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!