Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HT_JDC
New Contributor II

Addition of alias name after establishment of SD-WAN

Hello Experts,

I'm curious about addition/change of alias name for interface at SD-WAN.

Here is our situation.

 

At SD-WAN, we use IPsec aggregation called "AGG" which consists of WAN1 and WAN2
At first, we confirmed both SD-WAN and AGG were established.
Next, we added alias name for WAN1 and WAN2, such as SAT1 and SAT2.
After the addition of alias, SD-WAN was down, although IPsec aggregation itself was established.

 

Is this situation kind of SD-WAN specification?

When we created SD-WAN, we should have added alias name, I understand.

 

Any comments are helpful.

4 REPLIES 4
funkylicious
SuperUser
SuperUser

hi,

SD-WAN uses zones, virtual-wan-link being the default one and cannot be deleted but you can create other(s).

in it, you add/assign the members but the alias has no relevance as far as i know and adding an alias to an interface should not bring down the interfaces.

can you share the changes you've made and how it looked after?

"jack of all trades, master of none"
"jack of all trades, master of none"
rosatechnocrat
Contributor III

That's correct, adding an Alias will not bring interface down. There might be some other reasong for the link going down. You can check system event logs for the interface or SDWAN interfaces going down. 

Rosa Technocrat --

Also on YouTube---

Please do Subscribe
Rosa Technocrat --Also on YouTube---Please do Subscribe
HT_JDC

Hello,

 

We created new zone called "SDWAN" (default is not used).

WAN interface itself is not down.

Each IPsec tunnel of WAN is not down.

IPsec aggregation is not down.

Only SDWAN is down after addition of alias. Red sign is seen at performance SLA.

 

The fortigates are not at our hands now.

After we reproduce it, I will come back here.

 

Thanks,

kolaktu2
New Contributor

IIRC, you just need to give the user account running the command Full Control on the computer account itself and even that can be removed after the operation. Complete non-issue, especially since supposedly the user is already an admin of the device in question.

router login 192.168.l.l
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors