Fortinet Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Yahowmy
New Contributor

SD-WAN Rule let other IP than configured.

Good day,

 

I have created an SD-WAN rule that assigns specific wan interface for specific FSSO group, the strategy is manual so only the specified FSSO group's users can use this wan interface as a destination.

 

The issue is when reviewing forward traffic logs and filter the same wan interface from the SD-WAN rule i can see that almost all other IPs are using this interface!

 

What could be the issue here?

 

Bests. 

4 REPLIES 4
ShawnZA
Contributor II

I am going to guess other traffic is hitting the default rule below the one you created.... and that default rule will balance it over the SD wan interface members as per the settings of the that rule.

 

You need to create more rules for other traffic to use other interfaces or that default rule will still throw traffic over all the SD WAN interface members.

Yahowmy

Hello ShawnZa,

 

Yes, creating another rule for other traffic worked.

 

Thanks.

supportombm
New Contributor III

Which one is your primary SD-WAN?

Because if that is literally the first SD-WAN connectivity than everyone use that. You should add a rule for the "other" traffic to choose the secondary lan.

Ex:

FSSO PRIMARY -> WAN1

OTHER TRAFFIC -> WAN2

Yahowmy

Yes, i did that and it worked.

 

Thanks.