Description | This article describes how to create a configuration for FortiGate to decide what is the best (based on SLA targets) SD-WAN member to be used by FortiGuard and Default DNS Systems. |
Scope | FortiGate. |
Solution |
set primary 96.45.45.45 set secondary 96.45.46.46 set interface-select-method sdwan end
Technical Note: Routing Change and Session Fail-over with SD-WAN
FortiGate # diagnose sys sdwan service 1 Service(1): Address Mode(IPV4) flags=0x200 use-shortcut-sla When the values of the SD-WAN health check exceed the predefined values, the SD-WAN will send the packets to the best link. FortiGate # diagnose sys sdwan health-check FortiGate # diagnose firewall proute list id=2134048769(0x7f330001) vwl_service=1(FortiGuard_DNS) vwl_mbr_seq=3 1 dscp_tag=0xff 0xff flags=0x0 tos=0x00 tos_mask=0x00 protocol=0 sport=0-65535 iif=0(any) dport=1-65535 path(2) oif=12(wan-b) oif=11(wan-a)
FortiGate # diagnose ip address list | grep index=12 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.