Skip to main content
sw2090
SuperUser
SuperUser
January 11, 2018
Question

WLLB contra Policies on WAN Interfaces - any advices?

  • January 11, 2018
  • 5 replies
  • 5502 views

Heyho,

 

I have the following (not really uncommon *g*) setup:

 

FortiGate is connected to a router via one WAN Interface and to annother router via annother WAN.

Both WANs are in WLLB and doing some Loadbalancing.

 

Now let's say WAN1 has a static IP setup to reach that router and the WLLB knows the Gateway. Default Route is on WLLB.

Internet + WLLB works fine so far.

 

However it is impossible to create a policy granting access from somewhere inside to the Net the WAN1 is in because you cannot select WAN1 as destination nor source interface anymore.

I come in via remote by IPSec VPN and want to be able to access that router from here. That would require a policy at remote sinde but as I said I cannot create it.

 

Can anyone help me to understand why fortinet made this limitation? I cannot see any sense in not allowing this.

    5 replies

    Anurag_Goyal
    New Member
    January 11, 2018

    you can do all the things as you want but you need to share the model of FGT with version.

    sw2090
    SuperUser
    sw2090Author
    SuperUser
    January 11, 2018

    This ist not a model specific issue. I encountered this on a 100D,100E,60E,90D,...

    I'd consider it to be more a  "Feature" of FortiOS v5.4.x or greater.

    It generally happens to you on v5.4.x (I don't have any v5.6.x so can't say if it is there too) and it does not matter which FGT model you have alas it is able to run 5.4.x of course ;)

    Anurag_Goyal
    New Member
    January 11, 2018

    "However it is impossible to create a policy granting access from somewhere inside to the Net the WAN1 is in because you cannot select WAN1 as destination nor source interface anymore."

    1. Define the IP of your router in "Addresses" with particular interface.

    2. Create the policy "Source-your inside interface with your desired user's ip/IPSec user or all", Destination-WLLB with your router's IP as you created.

    that's it.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.