FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jclar
Staff
Staff
Article Id 322465
Description This article illustrates the parameters to consider when setting up secondary WAN on FortiGate with DHCP or PPPoE setup.
Scope

FortiGate.

Solution

In this scenario, the admin wanted to set up a secondary WAN for backup purposes. Primary WAN is configured with static IP however, the admin wants to install DHCP for secondary WAN.

 

WANDHCP.PNG

 

The routing table below shows the initial setup of the admin. No secondary WAN is connected yet.

 

Primary WAN routing table.png

When the secondary WAN is installed, users behind the firewall would probably lose connection to the internet. If checking the routing table,  the secondary WAN takes the default route.

 

Secondary WAN routing table.png

 

Solution:

DHCP or PPPoE interface has a setting of distance that needs to be considered. The default distance configured on the interface is 5. When checking the routing as shown above, the same value of distance reflects on the routing table.

Below is the default distance setting of the interface:

 

Secondary WAN interface.png

 

Change the distance to a higher value than the distance configured on the primary WAN. In this case, the default static distance is 10. Change the distance to 15 and notice that the routing table below takes back port1 as the default route.

 

Routing Table Primary route.png

 

WAN2_Distance15.png