Skip to main content
Superpacket
New Member
August 31, 2023
Solved

Two internet connections one ISP

  • August 31, 2023
  • 8 replies
  • 2965 views

Hi Team,

 

We have a scenario where we want to have two internet output connections to the same ISP, one connection over the WAN with public IP (which is already configured), and the second connection is to be on another LAN interface with private IP. Please check the details below:

 

The connection is as follows: 

 

Users-->proxy server-->Fortigate-->ISP router-->internet

 

this connection is going through the WAN public IP.

 

We want to enable another interface that will be connected to the ISP router with DHCP config to obtain IP/GW, and to influence the traffic to specific destinations to go through the new connection (private IP) using PBR.

 

The issue we are facing is that once we enable the interface (for example int 5) with DHCP config the internet connection goes down even without using it in any sort of policies.

 

Thanks. 

 

Best answer by hbac

Hi @Superpacket,

 

When using DHCP, it will automatically retrieve a default route from DHCP server as well and the that default route has an administrative distance of 5 by default (This route will not show up on the GUI).

 

You can disable it on the FortiGate GUI > Network > Interface > interface 5 > Disable "Retrieve default gateway from server". 

 

After that, you can configure policy routes and firewall policies to specific destinations to go through the new connection and test. 

 

Regards, 

8 replies

srajeswaran
Staff
Staff
August 31, 2023

Not sure if it is due to the lower default route priority received via DHCP. Can you try configuring a higher priority (greater than 10 of static route) and check?

Ref:https://community.fortinet.com/t5/FortiGate/Technical-Tip-Override-default-route-settings-default-route/ta-p/192605

Superpacket
New Member
August 31, 2023

Thanks for the prompt response. 

We checked the static route via GUI after enabling the interface and during the internet is down, there is only one default route to the WAN interface. 

srajeswaran
Staff
Staff
August 31, 2023

On the traffic logs, do you see any reason for traffic drop ? Can you share any instance of the dropped traffic log?

hbac
Staff
hbacAnswer
Staff
August 31, 2023

Hi @Superpacket,

 

When using DHCP, it will automatically retrieve a default route from DHCP server as well and the that default route has an administrative distance of 5 by default (This route will not show up on the GUI).

 

You can disable it on the FortiGate GUI > Network > Interface > interface 5 > Disable "Retrieve default gateway from server". 

 

After that, you can configure policy routes and firewall policies to specific destinations to go through the new connection and test. 

 

Regards, 

Superpacket
New Member
September 4, 2023

Hi @hbac 

 

That solved the issue, thanks a lot.

 

Regards,

tanzo
New Member
August 31, 2023

I was planning for ER605 but sadly it doesn't have a gigabyte port so speeds are capped at 100 Mbps as other companies like Trendnet and Edgerouter aren't available in India and importing one will make it difficult to claim warranty incase anything happens

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!