Created on
07-29-2025
01:21 AM
Edited on
09-10-2025
03:51 AM
By
Jean-Philippe_P
Description |
This article describes how Failover between Virtual IPs (VIPs) assigned to different ISPs on a FortiGate can be effectively implemented using SD-WAN with link health monitoring, along with proper VIP and firewall policy configuration. This approach ensures seamless service continuity by automatically redirecting traffic through an alternate ISP when the primary link fails. |
Scope | FortiGate. |
Solution |
A web server hosted in the internal network needs to be publicly accessible. Two ISPs are in use, each with a distinct Virtual IP (VIP) mapped to the same internal server:
Automatic failover is required so that if ISP1 becomes unavailable, inbound traffic is redirected through ISP2, and vice versa.
Failover Behavior.
To ensure seamless failover, external DNS failover can automatically update the public DNS entry from VIP1 to VIP2.
Related documents: Technical Tip: Virtual IP (VIP) port forwarding configuration |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.