Skip to main content
capricorn80
New Member
September 2, 2018
Question

Redundant wan link for Internet, IPSec and SSL VPN on Fortigate 5.6

  • September 2, 2018
  • 9 replies
  • 18992 views

Hi!

 

I have to implement redundant wan link and as per reading I think SD WAN is mostly towards load balancing. I have seen couple of videos of link monitoring and setting up redundant wan link. I also saw a video or read some where to create Zone instead of creating dual policies. Not sure if I recall well but it will be problem creating dual policies for WAN1 and WAN2.

Also my plan is to have redundancy for IPSEC and SSL VPN.

 

Can anyone guide me how to implement Reduandant link with best practices that includes less firewall rule like not creating two rule i.e. one for wan 1 and one for wan2.

How can I implement IPsec and SSL Vpn using reduandant link.

 

Thanks.

    9 replies

    Ashik_Sheik
    New Member
    September 2, 2018

    Hi ,

     

    SD Wan is the best option for Redundant WAN Connection .You need one rule and one route as well .After adding WAN1 and WAn2 to SD wan ..you can select best loadbalancing methods .

     

    Then in the policies only one policy eg : LAN to SDWAN policy need to create ..

     

    Also in the route one default route need for all the SDWAN members .

     

    Before adding the members to SDWAN u should remove all the interface dependencies ...

     

    SSL VPN -You should select both WAN1 and WAN2 inetrface in the SSL settings ..

     

    IPSEC-You should create 2 tunnel ..one under WAN1 and One under WAn2 for same destination ..

     

    I gave very brief idea on each section .There are many few configuration need to perform to achieve this .Let us know if you need more info on each section .

     

    Regds,

     

    Ashik

    capricorn80
    New Member
    September 2, 2018

    Thanks Ashik.

     

    SD WAN is for load balancing and in our case we just want to use one line until it goes down. I can think of it having setup to use both the link and maximize the traffic on our primary link.

     

    SSL VPN -You should select both WAN1 and WAN2 inetrface in the SSL settings:

     

    How will this make decesion if the traffic goes via WAN1 or WAN2?

     

    I am reading the docs and checking video link but if you have some doc links please share.

    Ashik_Sheik
    New Member
    September 3, 2018

    Hi,

     

    SDWAN by default will give you redundancy .You can also set link load balancing where you can select weight LB .If you need primary link to take full load then give 90% weightage to WAN1 and 10% to WAN2 or you can use Spillover as well .

     

    SSL VPN can be accessed by both the links simultaneously  .Better to FQDN for VPN in your public DNS and assign 2 A record WAN1 and WAn2 IP.

     

    Regds,

    Ashik

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!