Skip to main content
icoskun17
New Member
June 3, 2020
Question

VPN Branch to HQ Internet - Specific Interface Only

  • June 3, 2020
  • 1 reply
  • 2440 views

Hi,

     I have 2 Fortigates.  I need devices connected to one physical interface on the Branch Fortigate to use internet from the HQ Fortigate.  All other traffic on the Branch (other interfaces) can use local WAN interface for internet.

How do I do this?

Thank You

Ismail

    1 reply

    MattyG2787
    New Member
    July 27, 2020

    This should be in another thread but the simplest (cleanest) way is via SD-WAN rules

     

    Create your first SD-WAN rule to have 

    Src - HQ source

    DST - all

    Included Members - HQ Link

    Services - all

     

    Second rules

    Src - Other IP Ranges

    dst All

    Included Members - Local WAN

    services all

     

    This also pootentially allows the local internet to be used in case HO link drops (by changing second source to all)