Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

Nik
New Contributor II

SD-WAN and interface preference

Hi,

I am using sd-wan and until now I did not have problem with it. I did an upgrade yesterday to version 6.4.5 and now I am facing some problem. Some system which are reachable on the internet are not answering because I think we are going out with wrong public IP address. We are using volume alogorithm and of cource the sd-wan itself will distribute even the traffic and thats why we are facing this issue, however I dont know why this issue were not present before.

Can I solve this issue by creating a sdwan rule with interface preference? Is it the only thing I need to do, or should I do something else beside sd-wan rule?
3 REPLIES 3
ShanWill
New Contributor III

I have run into this same issue. What i have done to solve it is create an SDWAN rule. Create an FQDN address object to the url and in the SDWAN rule specify traffic going out to that object to use a specific wan interface of the SDWAN interface. That way no matter what it will always appear as the same IP address from the FQDN you are accessing.
Nik
New Contributor II

Thank you for the answe Shane. I think we will go and implement this one.
ShanWill
New Contributor III

here are some screenshot examples
this is the FQDN address for gmail ( mail.google.com ) as an example

MessageImages_856bd8107f0c4426a769e616873607ce.png
The rule would be source : all or whatever else would apply in your scenario with destination the created address object using manual outgoing interface and select which to use

MessageImages_a6ec58a9b029459194245a87275b1197.png

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.