Skip to main content
cedwards
New Member
October 21, 2022
Question

Issue with SDWAN, Policy Routes, and OSPF

  • October 21, 2022
  • 2 replies
  • 3043 views

I have a Fortigate 60 F connected to 2 FPOE248 switches via Fortilink. 

 

WAN 1 of the Fortigate connects to a router which provides connectivity to a private WAN, that is also the primary internet access. WAN2 connects to a cable modem that is intended to be a failover Internet.

 

Port 1 is the gateway for the locations LAN. Port 2 is the gateway for the WiFi LAN. Port 1 is a member of OSPF and is receiving a default route. A Policy route in the 60F is sending traffic from Port 2 out WAN2, so as to prevent the WiFi traffic from traversing the private WAN. All traffic was functioning as intended in this configuration.

 

As I have done before on other 60Fs, to allow the internet traffic from Port 1 to failover to WAN2, I setup SDWan with WAN1 and WAN2 as members. Manual failover was setup with WAN1 preferred. I implemented IPSLA. At this point, despite WAN1 being the preferred interface, all traffic was exiting WAN2. Both interfaces showed up in the IPSLA. Removing WAN1 from the SDWAN fixed the issue with that Port1 traffic exiting WAN2, when WAN1 was still up, but at this point WiFi traffic stopped working. I eventually had to bypass the 60F entirely to get WiFi restored.

 

Has anyone had an issue with SDWAN and default routes from OSPF? I've used the SDWan and Policy routes before with no issues. Any thoughts?

2 replies

distillednetwork
Explorer II
October 23, 2022

could you post your policy route and sdwan configuration?  SDWAN basically creates dynamic policy routes in the background and you could have a conflict with this.  

 

When the issue is occurring you could run:

diag firewall proute list

to see how the proutes are listed in the kernel

 

cedwards
cedwardsAuthor
New Member
October 24, 2022

All the SDWan configuration was ripped out to get the LAN traffic working correctly.

 

Here is the one policy route I configured:

 

# show router policy
config router policy
edit 1
set input-device "internal2"
set src "0.0.0.0/0.0.0.0"
set dst "0.0.0.0/0.0.0.0"
set gateway 10.1.10.1
set output-device "wan2"
next
end

 

When I'm able to schedule an outage to implement the failover I'll run the diag command.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.