FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Kush_Patel
Staff
Staff
Article Id 268299
Description This article describes how to allow only certain traffic from specific sources to pass through the secondary link.
Scope FortiGate.
Solution

In this example, SD-WAN is configured for a failover purpose and the desired result is to allow only certain traffic from a certain source to be allowed over the secondary link due to bandwidth concerns, but the implicit SD-WAN rule will allow access to all sources and there is no restriction control in firewall policy for only the secondary link.

 

Control over individual link on firewall policy level is achievable by using different SD-WAN zones. Put the primary link into one SD-WAN zone and the secondary link into another SD-WAN zone.

 

This way, it is possible to configure a policy to allow traffic to go through the secondary link for only certain users/IPs.

 

Create SD-WAN zones as follows by going to Network -> SD-WAN -> SD-WAN Zones:

 

zone.png

 

Configure SD-WAN rules for failover by going to Network -> SD-WAN -> SD-WAN Rules:

 

sdwanrule.png

 

Configure Firewall Policies for granular control over specific links for specific traffic:

 

policies.png

Contributors