HA WAN Design.
Hi Folks,
Our current WAN backup line isnt working, passes traffic fine but we need to implement BGP. I am thinking of gutting it and starting from stratch.
We have two fortigates HA A/P config. At the moment it just uses static routing. See below. This works OK but we need to implement BGP on the external switches for route advertisement for inbound traffic. (Static with our ISP atm).
However we have a further issue. We are migrating to AWS. The AWS tunnel keys off our WAN1 (fortigate 123.123.123.2) address. Therefore if we get a senario were WAN2 has to take over traffic our VPN tunnel to AWS will drop.

I am thinking of replacing the entire setup with the below. So remove WAN2 (as its IP would never connect to the AWS tunnel). Does this design make sense, using HSRP between the two external switches, the fortigate would have static external route to the HSRP address and the external L3 switches would handle the BGP (our ISP will only add these to the BGP neighbours, I was originally hoping we could do it from the Fortigates but no)

Feel free to offer constructive criticism etc. Opinions, will it work etc.
Chris.
