Skip to main content
migell
New Member
January 3, 2025
Question

SDWAN SLA Limitations

  • January 3, 2025
  • 2 replies
  • 1525 views

With a limit of 10 SLAs per zone I'm a bit stumped.

I have roughly 80 remote sites all connectong to the same hub, with 2x dialup tunnels per site. So 160 IPSec tunnels in the overlay.

While each remote site can have its own SLA up to the Hub I can only configure 10 SLAs from the Hub to remote sites https://19216801.onl/ .

This causes some performance issues for traffic sourcing from the Hub as it's path selection isn't checking the quality of the tunnels for all the remote sites.

So what now?

2 replies

funkylicious
SuperUser
SuperUser
January 3, 2025

Can you share where you found this limitation?

If I visit the link, https://docs.fortinet.com/max-value-table , I find for 60F/200F/600F for system.sdwan:health-check values of 4000.

"jack of all trades, master of none"
Jeremy5385
Visitor III
January 3, 2025

I would open a support ticket on this one.  I have a hub with 20 spokes, roughly 80 tunnels (2x2).  The hub has a SLA for each site with the four tunnels to the site.  I then have a SDWAN rule per site with the destination IP range and the four tunnels.  I have had no issue with going past 10.  FGT 7.4.4. 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!