Skip to main content
wize
New Member
April 2, 2026
Question

SD-WAN member with VPN tunnel and internet service access

  • April 2, 2026
  • 1 reply
  • 124 views

I have are two Fortigate firewall between model 50G and 50G-WIFI. Also use SD-WAN to created dual internet and its through SD-SLA mark the auto fail-over.

 

In my case has an interesting problem occurred:

***also use the same as police & static route 

 

Model 50G-WIFI:
SD-WAN member: 
VPN_01, VPN_02 => enable
Wan, A=>enable

 

that are two VPN tunnel & internet service also work as well.

===============================

Model 50G:

SD-WAN member:
VPN_01, VPN_02 =>enable
Wan, A=>enable

VPN with Phase1 =>lost

====
SD-WAN member:
VPN_01, VPN_02 =>enable
Wan, A=>disable
VPN service work as normal

====

SD-WAN member:
VPN_01, VPN_02 =>enable
VPN service work as normal, internet service not working

as above case problem, how can to resolve it?

 

 

1 reply

kaman
Staff
Staff
April 4, 2026

Hi wize,

This issue is observed due to incorrect routing behavior when underlay (WAN) and overlay (IPsec VPN) interfaces are combined within the same SD-WAN zone on the FortiGate. When WAN is enabled as an SD-WAN member, IKE (Phase1) traffic follows the SD-WAN service rules instead of the routing table, leading to incorrect egress interface selection and Phase1 negotiation failure. This results in VPN tunnels going down, while removal of WAN restores correct routing and tunnel establishment.


To resolve, it is recommended to bind each IPsec Phase1 interface explicitly to the correct WAN interface, and configure a static route for the remote gateway IP to ensure deterministic IKE path selection. Additionally, separate SD-WAN zones should be used for underlay (WAN) and overlay (VPN) interfaces to avoid routing ambiguity. SD-WAN health-check (SLA) and service rules must also be validated to ensure proper member selection.


Reference Documents:
https://docs.fortinet.com/document/fortigate/7.0.1/administration-guide/942095
https://docs2.fortinet.com/document/fortigate/7.2.8/administration-guide/942095
https://docs.fortinet.com/document/fortigate/7.0.0/sd-wan-sd-branch-deployment-guide/176458/adding-sd-wan-members-to-underlay-zones

If you have found a solution, please like and accept it to make it easily accessible to others.


Regards,
Aman

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.