Skip to main content
frct
New Member
April 5, 2019
Question

How to rely each LAN to a specific WAN

  • April 5, 2019
  • 1 reply
  • 6226 views

Hi everyone,

First of all sorry for my bad English,

 

I have 2 LAN on my FortiGate 51E v6.03 : one on a hardware switch on port LAN 1 and a second on a other hardware switch.

WAN 1 : ISP 1 Fiber

WAN 2 : ISP 2 LTE

 

I want that LAN 1 use only WAN 1 and  LAN 2 only WAN 2.

I have one VPN per LAN.

 

I have some policy who allow lan to join the dedicated WAN but when the two WAN are up, both client in LAN 1 and LAN 2 doesn't have internet access.

 

I tried these policy :

https://forum.fortinet.com/tm.aspx?m=157824

https://forum.fortinet.com/tm.aspx?m=127289

 

but still don't work with the two wan,

I can take screenshot of the policy if it can help.

 

I will force all the traffic from LAN 1 to pass through WAN 1 , idem for LAN 2 and WAN 2.

 

best regard

 

 

 

 

1 reply

lobstercreed
New Member
April 5, 2019

Several solutions come to mind including things posted in the two posts you linked, but the easiest might be to use the SD-WAN feature.  This may require some rebuilding of your config if you already have policies associated with particular WAN interfaces, but the end result should be better.  If you put both WAN ports into an SD-WAN and configure as you like, you can add an SD-WAN rule to specify that LAN 1 traffic should go out WAN 1 another rule to specify that LAN 2 should go out WAN 2.

 

https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-networking/SD-WAN/Configuring_SD-WAN_rules.htm

 

https://cookbook.fortinet.com/redundant-internet-with-sd-wan-60/

frct
frctAuthor
New Member
April 5, 2019

I look at this this Monday, thx