Created on
09-20-2023
10:02 AM
Edited on
06-23-2025
08:44 AM
By
Stephen_G
Description | This article describes how to set up SD-WAN failover between two/three WAN ports in FortiGate. |
Scope | FortiGate. |
Solution |
Prerequisites: On the FortiGate system, two/three WAN interfaces are correctly set up and linked.
Configuration Steps:
Note: When the route under SD-WAN is already created, there is no need to create a static route for independent WANs (WAN1, WAN2, WAN3, etc.) because they are already included in the route for the whole virtual-wan-link (SDWAN Zone), which already has the WANs internally.
Testing and Monitoring:
It is essential to test and keep an eye on the system after installing SD-WAN failover amongst two/three WAN interfaces to ensure efficacy.
Here are a few suggestions:
A check sign will be seen beside the selected interface that is processing the traffic. In the below screenshot, it is possible to see that from all 3 interfaces, wan1 is selected as the outgoing interface.
When wan1 is down, the traffic will be processed by wan2:
Track the performance and status of each WAN link by checking the SD-WAN dashboard in the FortiGate administration interface.
Review the SD-WAN logs and reports frequently to spot any problems or irregularities.
Troubleshooting: Check the WAN interfaces' physical connections and set-ups.
The following commands are useful for troubleshooting an SD-WAN environment.
diagnose sniffer packet
diagnose debug flow
diagnose system session list
Feel free to open a TAC support case if require any further help. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.