Ipsec vpn and sdwan performance SLA issu
Hi All,
one of my customers has two branches, each one with a Fortigate 40F. Both appliances use SDWAN to balance outgoing traffic between two ISPs each has 2 ipsec tunnels pointing at the other branch and 4 ipsec tunnels pointing at their AWS instances.
The routing for th vpns was configured with static routing but I wanted to use SDWAN also for the ipsec traffic, so I crerated new SDWAN zone and members for the tunnels pointing at AWS. I followed this Technical Tip except for the fact that the tunnels were create previously so I just added them to the new sdwan zone and set a performance sla source IP via the cli.
Now the new sdwan zone works fine, I've tried knocking down the tunnels one by one and the ping sessions to AWS stayed up perfectly, on both Fortigates. Though if I look at the performance SLA's tab one fortigate shows as if only one tunnel was working, while the other shows as if none of the tunnels worked.
I'm posting a couple of screenshots:
Performance SLA's of Fortigate1

PErformance SLA's of Fortigate 2

