LLB rules for using different wan interface depeding on source
- February 23, 2017
- 6 replies
- 14554 views
Hello,
I am new to Fortinet world. I would like to configure fortigate to use different wan interfaces depeding on source address. For example, servers placed in DMZ should use wan2 interface, users in lan/guests should use wan1.
So, I configured (see picture at the bottom of this post):
- WAN-LLB: I set wan-load-balance interface with wan1 and wan2 interfaces
- Static Route: I set for destination 0.0.0.0/0.0.0.0 the device wan-load-balance
- WAN-LLB Rules: for test purpose, I created two rules:
[ol]In this case, all seems to work. Clients in lan that surf in www.dnsstuff.com see in the web page that the public ip address used is the one of wan1, clients in DMZ see public ip of wan2.
Then I changed destionation address from "dnsstuff" to "all". In this case, all firewall rules don't work. I ran a traceroute from a client lan address to a dmz client address, the first hop is not the lan interface address, but the default gateway of wan1. So that rule replaced the default gateway of all interfaces with the default gateway of wan1/wan2.
Is there any way to select as destination of WAN-LLB rules "all internet addresses" instead "all"? Or, is there any other way to get what I want?
Thanks
eclipse79

