Been witnessing an issue where spoke to internet traffic via hub would see excessive latency via Tunnel 1 (WAN 1) despite the rule failing over to Tunnel 2 (WAN 2) based on SLA metrics.
Traffic between spoke and internal subnets behind the hub is fine as those do switch to Tunnel 2.
Traffic from spoke to local WAN 1 internet break out is also fine.
Anyone familiar with this issue?
Hello kriyapedo,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Hi,
You are not really giving a complete picture, how are routes added, bgp or static, is the internet part of the sd-wan overlay etc?
A few thoughts.
diagnose sys sdwan health-check on the hub
- Confirms that the health‑check for WAN 1 is actually failing.
diagnose sys sdwan neighbor on the hub
get router info routing-table static and bgp on the hub
get router info routing-table bgp on the spoke
| User | Count |
|---|---|
| 2892 | |
| 1448 | |
| 848 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.