Description | This article describes how to set up an ISP Failover using static routing and link-health monitor |
Scope | FortiGate V7.x. |
Solution |
Note1: After enabling 'Multiple Interface Policies', add multiple interfaces to a single policy.
Note 2: It is important to note that when distances are equal, both routes will be included in the routing table. However, the route with the lower priority will be preferred. The s* symbol indicates that this route is the primary route to the internet.
If assigning a higher distance to WAN2, it will be removed from the routing table and will no longer be usable. If the goal is to keep WAN2 available for specific routes, port forwarding (VIP), or management access, it is better to use the configuration option mentioned above.
The WAN2 default route has been removed and is no longer available for use.
To keep one of the interfaces as a DHCP client, to achieve ISP Failover, assign a higher distance to the other interface.
The basic settings of the ISP Failover have been completed. The steps mentioned will work if having a physical or logical shutdown of any of the WAN interfaces, but if internet service is lost on the ISP modem, Failover may not be done. To avoid this issue, it is necessary to configure a link health monitor. To accomplish this, follow this KB article: Technical Tip: Link-Monitor Explained
For further assistance, reach out to the TAC support team
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.