Skip to main content
aymericQA
New Member
November 9, 2021
Question

How to direct some IPSec traffic to specific Wan interface ?

  • November 9, 2021
  • 1 reply
  • 2088 views

Hello, 

 

I have a Fortigate FG100D.

Here's the context. I've got some IPSEC tunnels working with my wan1 interface. Some "static" site to site, some dynamic with Forticlient endusers.

I'm switching to a new Internet access provider, linked on wan2.

The default route is still wan1

I want to gradually switch my tunnels on wan2. So i "copy" my IPSEC tunnel with wan2 instead of wan1.

My forticlient client incoming on wan2 can't connect. I guess because I need to specify the return route to wan2 for establishing the tunnel.

I can't use policy based routing to divert all IPSEC tunnel traffic to wan2, because I still have some IPSEC tunnels on wan1.

Any idea how to do this ?

Thank you

Aymeric

 

EDIT: As expected, if i add a static return route to my clients through wan2. It works. Obviously, i can't add route to my clients using laptops and cellular network and forticlient.

 

Aymeric

    1 reply

    Julien87
    Contributor II
    November 9, 2021

    Hi Aymeric,

     

    Can you try with 2 two default route on FG100D with same administrative distance and if you want with priority different?

    You can check the route before and after changing this routing table.  in cli  get router info routing-table all

     

    You should have 2 entry for the default route (for example)

    FortiGate-VM64-KVM # get router info routing-table all S*      0.0.0.0/0 [1/0] via 10.10.17.254, port4                   [1/0] via 10.10.18.254, port2

     

    Best regards,

     

    Julien

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!