Skip to main content
Contributor III
July 22, 2004
Question

Multiple Gateways

  • July 22, 2004
  • 42 replies
  • 18167 views
We have just upgraded to Version 2.8 of the Fortigate OS. We used to be able to have 2 gateways setup per static route as we have both a leased line and ADSL connection running at the same time. This feature no longer seems to be available, as we would like to do source routing and our web browsing traffic out our ADSL line. Can this still be done?

    42 replies

    VicAndr
    New Member
    September 28, 2004
    This thread has been initiated more than two months ago and is the most visited in the " routing" forum. But it is quiet here now. There was one generally available maintenance release during this timeframe and some interim releases not pulished on the public ftp; did they fix the problem? Or maybe someone found a workaround? VA
    Contributor III
    September 29, 2004
    Hi I have too the same routing problems with ppoe interface. We have dual ISP, FG60 v280-build219. WAN1 is static IP and WAN2 is ppoe. Through WAN2 I want to pass only IP address range 212.59.0.0/16. All Other trafic through WAN1. Tryed diferent configs, but no luck (or did not find that workaround to overcome one more problem ). FG does not route as the normal router should, or I am a dump engineer [:' (]
    Contributor III
    October 5, 2004
    Any further comment on this? Since the fortigate doesn' t speak bgp, you can' t use ibgp to prefer async routes on the external interface(s). Mulitple gateways would be nice even if they just resulted in an even distribution by halfing the traffic. This is certainly the case where border routers speaking bgp are in use.
    VicAndr
    New Member
    October 6, 2004
    Well, multiple gateways and policy routing DOES work with FortiOS 2.8, at least for MR5 (didn’t try with previous versions). But with the FortiOS 2.8 Admin Guide it doesn’t clear how you could actually do it. We have 2 internet connections, both are with static IPs. When we were on 2.5 everything was clear and straightforward: one gateway is primary, where all traffic is forwarded to by default and second one is the secondary - to accept the traffic in case of primary gateway failure; both specified in a single route. Then with the help of policy routing you can force traffic to the secondary gateway when necessary. With 2.8 you do not have an option with 2 gateways in a single route any longer. At first it seemed to be obvious how I would configure the box to achieve the same goal: 2 static routes with different metrics pointing to different gateways; the route with the lower metric would be the primary (or default) and with higher metric – the secondary. Then, again with policy routing you could reroute traffic depending on your needs. I guess, most of us did the same thing and we know the result… After I spent some time trying to make it work I contacted Fortinet Support (they didn’t respond to my e-mail for 2 days, so eventually I had to call them). So here is my solution. To make it work with two gateways I had to configure 2 static routes. There are two important things here: 1. Both routes must have the same metric! 2. The primary (or default) route will be the one which is the second (lowest) in the list. As to the policy routing, it works as usually – there are no surprises here. There is only one little thing, which I am still concerned about: FortiGate interface associated with the secondary route does not respond to pings even if it is clearly enabled. Everything else seem (fingers crossed) to be working OK. I sent e-mail to Support with the question – so far there is no response (they became much slower in response – are very busy now ). VA
    VicAndr
    New Member
    October 6, 2004
    Here is responce from Fortinet Support: Victor, Go into the CLI via console or telnet. Type in:
    config sys global    set asymroute enable      end
    This enables asymetrical routing. Try the ping again.
    That' s what CLI Reference Guide (I' d love to have something more to read about this and other FortiGate' s features but it the only information source I' ve found) says about assemetric routing: Using asymmetric routing, packets that are part of the same session travel different routes and pass through different gateways. I am not sure here that for the sake of pinging I want to enable asymetric routing ...
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!