Skip to main content
bmzsbt
New Member
January 25, 2012
Question

Policy Routing with dynamic gateway possible?

  • January 25, 2012
  • 3 replies
  • 4917 views
Sorry for the newbie (to policy routing that is) question: FGT60C 4.0 MR3 Have a second ISP without a static public IP. The WAN2 Addressing Mode is configured DHCP and " Retrieve default gateway from server" is checked. Thus when creating a router Policy Route I don' t have a static gateway to use for the outgoing interface WAN2. Will the Fortigate use the DHCP gateway of WAN2 automatically? Or do I need to get a static IP from the ISP and not use DHCP Addressing Mode? At the end of the day I want outgoing traffic to go over WAN1 with the faster upload bandwidth and all incoming be WAN2 with faster download. But SMTP still must be WAN1 with the static IP.

    3 replies

    Fullmoon
    New Member
    January 26, 2012
    ORIGINAL: bmzsbt Have a second ISP without a static public IP. The WAN2 Addressing Mode is configured DHCP and " Retrieve default gateway from server" is checked. Thus when creating a router Policy Route I don' t have a static gateway to use for the outgoing interface WAN2. Answer:Lets say if you want to bend traffic leaving your LAN to the Internet then your PBR (Policy Based Route) must look like this Protocol=0 Incoming Interface=Internal(Interface facing your LAN side) Source add/mask=192.168.1.1/32 (this host should go out using WAN1 Link) Destination address/mask=0.0.0.0/0.0.0. Destinations Ports=From:1 To:65535 Force Traffic to: Outgoing Interface: WAN1 Gateway Add=0.0.0.0 or Protocol=0 Incoming Interface=Internal(Interface facing your LAN side) Source add/mask=192.168.1.2/32 (this host should go out using WAN2 Link) Destination address/mask=0.0.0.0/0.0.0. Destinations Ports=From:1 To:65535 Force Traffic to: Outgoing Interface: WAN2 Gateway Add=0.0.0.0 Will the Fortigate use the DHCP gateway of WAN2 automatically? Answer:No, if the distance of both WAN Links are identical then other traffic coming from your LAN may pass thru WAN1 or WAN2 links. IF you want all traffic must pass thru your WAN2 link then lower its Distance Or do I need to get a static IP from the ISP and not use DHCP Addressing Mode? Answer: If you can change the addressing mode from dynamic to static from your ISP then much better.
    regards
    bmzsbt
    bmzsbtAuthor
    New Member
    January 26, 2012
    Thanks, Fullmoon. I had distance of both WAN links identical. So, next I' m assuming I' ll need another PBR for the remaining internal LAN addresses to go out WAN2? i.e.: Source add/mask 192.168.1.0/32 Do I need a default static route too or will the PBRs handle all routing? In reading the Handbook it isn' t clear to me if it is both/and static and pbr or if it is either/or (one is to use one or other but not both).
    Fullmoon
    New Member
    January 26, 2012
    ORIGINAL: bmzsbt So, next I' m assuming I' ll need another PBR for the remaining internal LAN addresses to go out WAN2? i.e.: Source add/mask 192.168.1.0/32
    Hi,be careful of using this kind of notation 192.168.1.0/32. It seems invalid address. if you wish that whole subnet will pass thru on diff link then it should be 192.168.1.0/24 then if you want single ip address or host it looks like this 192.168.1.X/32. (X means your single host or ip)
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!