Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
spanz
New Contributor III

Redundant backup link to main branch

Hello,

 

I am running Fortigate 600e appliances in HA mode on the main branch.

I have all my branches connected to the main branch via MPLS.

 

I am setting up a new Fortigate 30e 3G4G INTL model with one MPLS link and one 4G sim-card connection which is IPSEC tunneled to the main branch.

 

The new branch will use 10.100.0.0/16 subnet for the LAN.

172.22.22.1/30 for the MPLS link with default gateway of 172.22.22.2/30

and a DDNS address for the 4G connection which is already established a tunnel with the main branch.

 

In the main branch, I have static routes for all of the branches local subnets (including the new one) routed to default gateway 172.23.19.130/30 (Service Provider machine), and being routed over the ISP machines to the destination branch (transparent for me).

 

I thought about setting up 2 default routes on the new branch

first 0.0.0.0/0.0.0.0, gateway: 172.22.22.2, Priority 0

second 0.0.0.0/0.0.0.0, gateway: TUNNEL_INT, Priority 10

Set a link monitor with src.int of the MPLS one, pinging internal server behind the main branch, and update the routes when it fails.

 

On the main branch, I can set 2 static routes.

first 10.100.0.0/255.255.0.0, gateway: 172.23.19.130, Priority 0

second 10.100.0.0/255.255.0.0, gateway: TUNNEL_INT , Priority 10

on this one, I'm afraid I cannot set the link monitor with src.int of the MPLS link since it will change all the routes for the other branches as well.

 

I'd like to know how can I set it right.

Also, I will appreciate second opinion of the whole process I described here.

 

Thanks very much.

span

 

 

3 REPLIES 3
Toshi_Esumi
SuperUser
SuperUser

If you're concerning about the MPLS link down only at the remote location, and you want to let HQ change route only for the prefix at the location to go to a direct VPN, you have to use a routing protocol instead of static routes. eBGP is probably the best for more control if the MPLS provider supports it.

 

Toshi

spanz
New Contributor III

Thanks for the reply.

But changing all routes is not in ny scope now, I have to make it work with static routes til I'll change it to dynamic routing.

Toshi_Esumi

What I'm saying is Not possible without routing protocol, because HQ would never know the remote location's link down without it. Only alternative is to get the secondary MPLS link at the remote location from the same provider so that the remote location still can failover to get to the same MPLS withough any involvement of HQ routing changes.

Labels
Top Kudoed Authors