FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Babitha_M
Staff
Staff
Article Id 247671
Description

This article describes the case when the user is not able to create multiple default routes when there are two ISP links, of which one is in SD-WAN and another is not in SD-WAN.

Scope All FortiGate.
Solution

It is necessary to either add the non-SD-WAN interface to the

SD-WAN or remove the configured interface from SD-WAN.

 

For example:

There are two WAN interfaces, one is wan1 and another is wan2.

The wan1 is a member of SD-WAN, and wan2 is not a member of SD-WAN.

 

There is a default route with the virtual WAN link with wan1.

When trying to create another default route with wan2, which is not part of SD-WAN, the duplicate error will appear.

 

Here is the error when trying to create a default route:

 

Babitha_M_0-1677670087154.png

 

There are a couple of methods to follow:

  • Divide these interfaces into 2 different SD-WAN zones. And use these zones while addressing them in routes or firewall policies.
  • In a static route, do not use the SD-WAN interface, but a specific interface. Then it will be possible to create the default route via any interface chosen, even the ones that are not part of SD-WAN configuration.