Skip to main content
RJ1
Explorer II
January 3, 2025
Question

FortiGate Virtual Interfaces Shows as down on the GUI, but in CLI, the interface is UP.

  • January 3, 2025
  • 3 replies
  • 1984 views

Internet and ADVPN interfaces are virtual on the firewall. When either the ISP or ADVPN goes down, the Firewall marks interfaces as DOWN on the GUI but in CLI, the interface appears up. Any suggestion on same, we are running FortiGate version 7.2.8

3 replies

kaman
Staff
Staff
January 3, 2025

Hi RJ1,

As you mentioned that the ISP goes down but still there were active route in the routing table. In FortiGate, the route preference will be first policy route and then SD-WAN routes.

Hence you should have a default route pointing toward the SD-WAN virtual interface this will help to route traffic with other interfaces when one link fails.

Please refer to the below article on how to configure an SD-WAN properly.

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/218559/configuring-the-sd-wan-interface

For your query make sure:
1. Static route is pointing to SD WAN zone:

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/626338/adding-a-static-route

2. Make sure the Performance SLA has the SD WAN members selected and 'update static route' enabled:

Note: If 'update static route' was disabled under Performance SLA then enabled the 'update static route' and check the routing table.

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/723056/link-monitoring-and-failover

If you have found a solution, please like and accept it to make it easily accessible to others.

Regards,
Aman

RJ1
RJ1Author
Explorer II
January 3, 2025

Thank you for your reply Aman, the issue is when ISP or ADVPN (Virtual interface) is down, it shows as "DOWN" in GUI but in CLI status is "UP"

kaman
Staff
Staff
January 3, 2025

Hi RJ1,
Can you please share the output of the CLI?
And GUI screenshot 

RJ1
RJ1Author
Explorer II
January 3, 2025

Unfortunately cannot share the screenshot, as the FWs are in production and the interfaces are UP now, so Once its down again will capture screenshot.

kaman
Staff
Staff
January 3, 2025

Hi RJ1,

If 'update static route' was disabled under Performance SLA then enabled the 'update static route' and check the routing table.

RJ1
RJ1Author
Explorer II
January 3, 2025

ok will do it and will let you know the output.