Created on
‎09-20-2023
10:02 AM
Edited on
‎10-07-2025
11:29 AM
By
Stephen_G
Description | This article describes how to set up a basic SD-WAN failover between two or more WAN ports in FortiGate. |
Scope | FortiGate. |
Solution |
Prerequisites:
Configuration Steps:
Note: When the route under SD-WAN is already created, there is no need to create a static route for independent WANs (WAN1, WAN2, WAN3, etc.) because they are already included in the route for the whole virtual-wan-link (SDWAN Zone), which already has the WANs internally.
Testing and Monitoring:
It is essential to test the system after configuring SD-WAN failover to ensure efficacy.
A check sign will be seen beside the selected interface that is processing the traffic. In the below screenshot, it is possible to see that from all 3 interfaces, wan1 is selected as the outgoing interface.
When wan1 is down, the traffic will be processed by wan2:
Track the performance and status of each WAN link by checking the SD-WAN dashboard in the FortiGate administration interface.
Review the SD-WAN logs and reports frequently to spot any problems or irregularities.
Troubleshooting: Check the WAN interfaces' physical connections and set-ups.
The following commands are useful for troubleshooting an SD-WAN environment.
diagnose sniffer packet any 'host <remote server IP address>' 4 1000 l
diagnose debug flow
diagnose sys session list
For a similar setup without of the use of SD-WAN, the article below can be of assistance. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.