FortiManager
FortiManager supports network operations use cases for centralized management, best practices compliance, and workflow automation to provide better protection against breaches.
axel_gonzalez_FTNT
Article Id 192448
Description
Limitation: FortiManager will only associate a single management IP address with a managed FortiGate at any given time. 

Traditionally this is the WAN IP address on the FortiGate. But what happens when that WAN interface on the FortiGate (or the path to that interface) is down?


Normally, the FortiManager would have to wait until the FortiGate has reestablished the connection.

This article explains how to take advantage of SD-WAN & IPSec to provide multiple redundant paths for the FortiManager to reestablish the FGFM tunnel to the IP address on the LAN interface of the FortiGate, instead of the WAN interface.
Note: You could use this same approach with a Loopback interface on the FortiGate as well.


Scope
This article only discusses how you can achieve redundancy by using VPN IPSec.

Solution


Get more information in attached articles:
How to control/change the FortiGate source IP for self-originating traffic : SNMP , Syslog , FortiAnalyzer , Alert Email , FortiManager
IPSEC Wizard in Device Manager (in FortiManager New Features Guide, v6.2).


Related Articles

Technical Tip : How to control/change the FortiGate source IP for self-originating traffic : SNMP , ...

Contributors