FortiOS 7.4 — Best way to route 100+ subnets into an IPsec SD-WAN zone?
Hi everyone,
I’m working on a FortiGate running FortiOS 7.4.x.
I have:
2 WAN interfaces inside virtual-wan-link (SD-WAN)
2 IPsec interface inside another SD-WAN zone called remote
About 100 different /24 subnets that should be routed into the remote zone (over the IPsec tunnel)
All internet traffic must go out through virtual_wan_link
The obvious solution is creating 100 static routes, one for each /24, pointing to the remote SD-WAN zone — but that’s not practical at all.
How do you guys handle large numbers of remote networks in SD-WAN deployments?
Thanks!