Skip to main content
tturba
New Member
February 9, 2017
Question

WAN LLB on Zone members?

  • February 9, 2017
  • 3 replies
  • 5439 views

Hello.

 

I've got FortiGate 140D with three physical WAN connections (using BGP). I've configured them as a one zone called "ISPs" and used in this manner with IPv4 Policies. I would like to create a WAN Link Load Balance between these interfaces, but I cannot choose them separately from the list (or not even as ISPs zone). Is there a possibility to use this zone members separately in WAN LLB and not deleting current Firewall rules with interface "ISPs"?

    3 replies

    Alby23
    New Member
    February 9, 2017

    Nope.

    When you create a zone you lose the control on the single interface but you see them as a whole.

    tturba
    tturbaAuthor
    New Member
    February 9, 2017

    Thank you for quick reply.

     

    So basically I must delete WAN interfaces membership from zone ISPs, and then set-up WAN LLB but what should I do with IPv4 Firewall Policies? Everywhere where used "ISPs" as interface should I place three interfaces and it will work?

    MikePruett
    New Member
    February 10, 2017

    Are you doing the BGP on the FortiGate itself or on an upstream switch?

     

    I prefer ZONEs to WLLB. It keeps things simple when you start looking at incoming traffic etc in my experience.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!