| Description |
This article describes the expected behavior of the session ID seen in the logs when traffic is being handled by the SD-WAN rule with the Maximize Bandwidth strategy. |
| Scope | FortiGate, SD-WAN. |
| Solution |
In this example, the SD-WAN rule has been configured as below:
config system sdwan
config health-check In the above: Port1 and Port3 are the SD-WAN members and the relevant health check servers and SD-WAN rule are configured.
Relevant Firewall policy for the outbound traffic is already configured. Also note that the default Hash mode i.e. load-balancing mode is round-robin and this article explains this configuration for the same for other Hash modes the same behavior should be seen in terms of Session ID but the load-balancing method would differ.
Below are the details for Hash Modes:
To verify if load-balancing is taking place,
In GUI:
It is noticed that both Port1 and Port3 show a tick mark which means load balancing is happening and this is based on the SLA target criteria met.
On CLI:
diag sys sdwan service Service(1): Address Mode(IPV4) flags=0x200 use-shortcut-sla Dst address(1):
On the CLI output, it is possible to see that both the interfaces Port1 and Port3 are selected as well.
Now the important thing to note is that even if the traffic is getting load balanced it will maintain a different session and this will be indicated in the logs as a different Session ID.
The log output shows traffic going to Facebook, and the traffic is getting Load balanced as Port1 and Port3 are being used.
The Session ID will be different for traffic going out via each interface and not the same. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.