Hello Experts,
I'm curious about addition/change of alias name for interface at SD-WAN.
Here is our situation.
At SD-WAN, we use IPsec aggregation called "AGG" which consists of WAN1 and WAN2
At first, we confirmed both SD-WAN and AGG were established.
Next, we added alias name for WAN1 and WAN2, such as SAT1 and SAT2.
After the addition of alias, SD-WAN was down, although IPsec aggregation itself was established.
Is this situation kind of SD-WAN specification?
When we created SD-WAN, we should have added alias name, I understand.
Any comments are helpful.
hi,
SD-WAN uses zones, virtual-wan-link being the default one and cannot be deleted but you can create other(s).
in it, you add/assign the members but the alias has no relevance as far as i know and adding an alias to an interface should not bring down the interfaces.
can you share the changes you've made and how it looked after?
That's correct, adding an Alias will not bring interface down. There might be some other reasong for the link going down. You can check system event logs for the interface or SDWAN interfaces going down.
Hello,
We created new zone called "SDWAN" (default is not used).
WAN interface itself is not down.
Each IPsec tunnel of WAN is not down.
IPsec aggregation is not down.
Only SDWAN is down after addition of alias. Red sign is seen at performance SLA.
The fortigates are not at our hands now.
After we reproduce it, I will come back here.
Thanks,
IIRC, you just need to give the user account running the command Full Control on the computer account itself and even that can be removed after the operation. Complete non-issue, especially since supposedly the user is already an admin of the device in question.
| User | Count |
|---|---|
| 2715 | |
| 1416 | |
| 810 | |
| 736 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.