Description | This article describes how to force traffic through only one SD-WAN member and drop if that interface is down/unavailable. In this example, there are two WAN interfaces (port1 and port2), and Netflix traffic is sent only through port2 and if the port2 goes down, the traffic will be dropped. |
Scope | FortiGate. |
Solution |
Step 1: Split WAN ports into two separate zones. Firewall policies for SD-WAN traffic must reference SD-WAN zones and not individual members.
Step 2: Create an SD-WAN rule to steer Netflix traffic through the port2 interface.
Step 3: Create a firewall policy to block Netflix traffic through the port1 interface.
Verification:
Step 4: Now, test the connection.
Traffic is routed via port2.
Step 5: Bring down the port2 interface.
Step 6: Check again.
When port2 is down, the traffic is dropped. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.