Skip to main content
maxwee
New Member
June 29, 2016
Solved

IPSec with ECMP Load Balance

  • June 29, 2016
  • 6 replies
  • 11061 views

Hi Guys,

 

Need the expert help here.

 

I've got 2 of Fortigate200D setup as Active-Passive. Both has got 2 WAN link to internet, configured with ECMP weighted load balance. I've got IPSec setup by our MPLS provider as backup link. This IPSec tunnel sits on a static IP on WAN1. Heres the thing, when both WAN are plugged in, I'm getting intermitten ping loss to IPSec router, but when only WAN1 is connected, all is good. I have tried to configure policy routes but to no avail. I'm 100% sure this has got to do with the 200D wan load balancing algorithm. Any experts care to share some advise or has anyone had previous experience?

 

Thanks!

 

 

    Best answer by Toshi_Esumi

    First I'm not an expert so please forgive me, but I'm wondering if just putting a static route for the IPSec destination (/32) toward WAN1 interface would work to nail the IPSec tunnel traffic for both directions while the rest follows the load balancing rules.

    6 replies

    kallbrandt
    New Member
    June 29, 2016

    Hello,

    please share the parts of your config that contains the wan LLB setup, the routing table, and the PBR-rules.

    PM or obfuscate the IPs if you don't want to share them.

    WAN-LLB has certain limitations in my point of view - Do you actually need both wan active at the same time, or do you just want a redundant way out to internet?

    maxwee
    maxweeAuthor
    New Member
    June 29, 2016

    Yea i need both wan to be active at the same time. due to the low internet bandwidth vs number of users.

     

    WAN LLB setup

     

    Static Routes

     

     

     

    PBR

    Incoming - lan

    Outgoing - wan1

    Source - IPSec Tunnel IP

    Destination: 0.0.0.0/0.0.0.0

    Gateway: wan1 gateway

    kallbrandt
    New Member
    June 29, 2016

    I understand. And I guess you have the same values for distance/prio on both routes, so that is not an issue. That part looks fine from what you posted here.

     

    Ok, on to the PBR then. Let's see if I understood you correctly. Feel free to tell me otherwise. :)

     

    From what you posted here, you'll need to specify the IPsec-interface as outgoing (it is mapped to WAN1 anyway), and also specify the destination network (since you only want to perform PBR on the traffic destined for the other side of the tunnel, not everything).

    If you use destination network 0.0.0.0/0 here, you will have to make rules for the networks that you don't want to do PBR on (the "stop policy routing"-option in the rule), otherwise you will force everything that way. Don't specify gateway if you don't have to. Keeping gw to 0.0.0.0 means the PBR will use the gateway specified for the network in the routing table.

     

    For example: I have a PBR rule from a source interface/network that use 0.0.0.0/0 as destination. Since I only want to perform PBR on traffic destined for internet, I created 3 rules that stops PBR to 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16 before the PBR rule.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.