Skip to main content
sean3
Explorer II
March 9, 2025
Solved

multi Required SLA Target or multi probing detect server?

  • March 9, 2025
  • 8 replies
  • 3226 views

greetings all,

I created two SLAs, they have the same settings (same interface participants, same SLA target, same link status metrics) but only with different detect server (probing target). SLA 1 probing 10.74.a,b, SLA 2 probing 172.29.x.y. 

2 SLA.PNG

configure.PNG

And, I added the two SLA under the same SD-WAN rule, which is with lowest cost (SLA)

sd-wan rule.PNG

the question is , what is the Boolean logic here? Let's say, 15 consecutive times of probing failure occurs to either one of the two (1 out of 2) SLAs , will the related interface become inactive? and will the SD-WAN switch to the secondary interface (the interface with higher cost)?

AND, what about if I add the two probing detect servers to the same SLA? and only use the one SLA under the SD-WAN rule?

two server.PNG

Thanks,

Sean

Best answer by sean3

great explanation, thanks a lot, we are almost there. Can you please review my thought here?

In practice, it seems both way :

  1. multi probing detect server configured under the same performance SLA, and use the single SLA under sd-wan rule;
  2. or single probing detect server for each performance SLA but both SLA being used under sd-wan rule

can bring the same operational result.

 

In way 1, both SLA servers must fail to consider the SD-WAN member as dead. If either of them is reachable, the member is considered alive. So, in this scenario, the SD-WAN rule will not switch to the other interface if only one of the SLA server is unreachable.

In way 2, just like you mentioned, it also works in the same way as way one.

In my production, I used the way 2, because I also need visibility of each SLA performance in fortigate and FortiAnalyzer for both detect server, if I add the two server under a single SLA, then I don't have a good visibility for each of the server (as being illustrated Technical Tip: SD-WAN Performance SLA with Multiple Servers ). And I don't want the sd-wan trigger the failover if only 1 SLA fails, instead I want the failover to occur when both SLA fail (for 15 consecutive times, in my case).

 

8 replies

shuabhs2
New Member
March 9, 2025

I prefer to SLA monitor services the end users care about. O365 environment? Why not verify that office.com is reachable/performant? Similar targets are available for Google, AWS, or target your cloud-hosted ERP platform.

sean3
sean3Author
Explorer II
March 11, 2025

thanks,

this is a hybrid environment. We are monitoring the reachability to Azure.

Could you elaborate a bit more?

In my case, we applied 2 SLA under the same SD-WAN rule. Could you please help to review the post from Dhruvin_pate down below your post? And my supplementary post after that?

Dhruvin_patel
Staff
Staff
March 9, 2025

Greetings!

 

If you have two separate Performance SLA Rules, both rules must fail simultaneously for the related interface to become inactive. Therefore, if only one of the two SLAs fails (e.g., 15 consecutive probing failures), the interface will not be marked as inactive, and the SD-WAN will not switch to the secondary interface.

 

When you configure multiple probing servers within a single SLA, it operates as an 'AND' circuit. This means that both probing servers must fail for the SLA to trigger a failure state. If only one server fails, the interface will remain active.

 

I hope I answered your query.

 

Regards!

sean3
sean3AuthorAnswer
Explorer II
March 10, 2025

great explanation, thanks a lot, we are almost there. Can you please review my thought here?

In practice, it seems both way :

  1. multi probing detect server configured under the same performance SLA, and use the single SLA under sd-wan rule;
  2. or single probing detect server for each performance SLA but both SLA being used under sd-wan rule

can bring the same operational result.

 

In way 1, both SLA servers must fail to consider the SD-WAN member as dead. If either of them is reachable, the member is considered alive. So, in this scenario, the SD-WAN rule will not switch to the other interface if only one of the SLA server is unreachable.

In way 2, just like you mentioned, it also works in the same way as way one.

In my production, I used the way 2, because I also need visibility of each SLA performance in fortigate and FortiAnalyzer for both detect server, if I add the two server under a single SLA, then I don't have a good visibility for each of the server (as being illustrated Technical Tip: SD-WAN Performance SLA with Multiple Servers ). And I don't want the sd-wan trigger the failover if only 1 SLA fails, instead I want the failover to occur when both SLA fail (for 15 consecutive times, in my case).

 

Dhruvin_patel
Staff
Staff
March 17, 2025

Hello Sean,

 

In way 1: It is correct , it will not move to another interface if either of them is reachable.

In way 2: it will not move to another interface unless particular SLA categorically being used in sdwan rules. 

 

Regards!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!