Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
JohnAgora
Contributor

2 ISP, no WAN Balance

Hello,

 

I have 2 ISP but I DON'T need WAN Balance nor failover.

What I need is:

1 ISP-A Default route (OK)

1 ISP-B For administration: 1 VPN, and Trusted hosts for SSH and HTTPS. (Problem)

 

How can I make the 2nd configuration?

If I put a route 0.0.0.0/0 with more distance or priority, traffic gets in, but response is done through ISP-B.

If I change the route to a more specific (for example 100.100.x.x) is works, but that is not what I want.

PBRs are not working.

 

Thanks!

15 REPLIES 15
romanr
Valued Contributor

Are you running 5.2.4?

 

This could be bug #0287871

Try running a "diag sniffer packet any "'ip host <src-ip> and tcp port 22' 4 0 a" in parallel - If your SynAck pkts leaves port1 - then this is a bug!!

 

It was resolved with 5.2.5...

pcraponi

Good catch... 5.2.4 has a bug about it... Is your case?

 

@romanr I did the Written exam on Pearson Vue and the pratical on Fortinet Office in Miami/USA. When you pass on Written exam, you can contact your Fortinet local SE and "win" an invite for the pratical exam.

 

 

 

Regards, Paulo Raponi

Regards, Paulo Raponi
JohnAgora

I guess that's the problem.

Anyhow upgrading will take a while (we must do some analysis).

I'll think if there's something to "fix" it temporarily.

 

Thanks for the help!

JohnAgora

#287871 says "Administrative access to the FortiGate using HTTPs and SSLVPN access with the second WAN interface may fail upon upgrading to 5.2.4."

Anyhow, SSH access also fails.

Is that normal?

romanr
Valued Contributor

Hi,

 

we ran into the same issue - as far as I remember SSH also did not work - any TCP related local traffic is routed incorrectly. I think ping did work..

 

br,

 

Roman

JohnAgora

Hello,

 

Exactly. We are experiencing the same issue.

Your fix was to upgrade? Anyone has a different one?

I put a more specific route (for my IP) and it worked, anyhow I would like a more complete fix (the problem with the route was that I was unable to reach the other IP).

 

Cheers,

Thanks!

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors