Skip to main content
amir_basic
New Member
April 1, 2020
Question

SD-WAN with Policy-Based NGFW mode

  • April 1, 2020
  • 0 replies
  • 1786 views

Hello everyone,

We are trying to setup SD-WAN on Fortigate 30E device with FortiOs 6.2.3 and 2 PPPOE WAN connections.

One ISP is one WAN port and other ISP is on Port 4 that is setup as WAN interface. Both ISP connections are tested individually and the connection is working as expected.

SD-WAN interface is created with 2 members with same cost (0).

Static route is created to subnet 0.0.0.0/0.0.0.0, interface SD-WAN, Administrative distance 1.

Central SNAT policy is created with Incoming interface: lan, Outgoing interface: both WAN ports, Source address: local subnet, Destination address: all, NAT turned on, IP Pool Configuration: Use Outgoing Interface Address, Protocol: any, Explicit port mapping turned off.

Security policy from lan to SD-WAN is created with Incoming interface: lan, Outgoing interface: SD-WAN, Source address: local subnet, Destination address: all, Schedule: always, Service: ALL, Action: Accept, Inspection mode: Flow-based.

When we set NGFW mode to Profile-based with Central SNAT turned On in System\Settings, SD-WAN works perfectly. Even with the SD-WAN rules, everything works.

When we set NGFW mode to Profile-based an create same security policy, there is no Internet access at all.

Are we missing something or SD-WAN does not work with Policy-based NGFW?

 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.