FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ChrisTan
Staff
Staff
Article Id 243796
Description This article describes the behavior of the SD-WAN rules configured in manual mode while the performance SLA failure affects the rule.
Scope FortiGate.
Solution

In manual mode, no health checks are used. As a result, decision-making closer resembles logic more than intelligence.

 

But If all health-check is indicating that an interface is dead, even if it is used in manual mode, this SD-WAN rule will be void.

 

147 # diagnose sys sdwan health-check
Health Check(14):
Seq(2 port1): state(dead), packet-loss(100.000%) sla_map=0x0
Seq(1 port4): state(dead), packet-loss(100.000%) sla_map=0x0

 

It would be confusing to enforce such interfaces in the SD-WAN rule, the SLA still affects the route.

 

A possible solution is to delete all SLAs regarding that interface so that the port would be invisible from 'diagnose sys sdwan health-check'.

 

The interface in manual SD-WAN rules would be selected as active and the rule would be working without effect by SLA anymore.

 

Note that the SLA cannot be deleted if it has been applied to some rules.

 

Special Scenario:

In a special case in FortiOS 7.2.5 or later, the SD-WAN member interface is down and the related route is removed from the active routing table however, when checking the SD-WAN rules page the interface status still shows up/green even. This is a known issue that was addressed starting from 7.4.4 FortiOS and later versions.

This issue was not addressed in FortiOS 7.2 releases. The issue is a GUI problem and does not affect the actual routing. The bug ID for this problem is 924693.

 

Related documents: 

Technical Tip: SD-WAN rule in manual mode and Performance SLA

Manual strategy