Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
damianhlozano
Contributor

An IP range to use specific SDWAN connection or none

Hello team!!

 

I need to do the following but I dont know how.

We have the only 2 WAN connections in the same SD-WAN

Everything is working fine, but now we need to specific IP range to use WAN2, and when WAN2 is down, this specific IP range should not use WAN1 connection (Should not navigate).

Is this possible to accomplish this with SD-WAN rules?

 

Thanks in advance.

Regards,

Damián

 

Damián Lozano
Damián Lozano
12 REPLIES 12
sjoshi
Staff
Staff

Hi damianhlozano,

 

Yes, it is possible.

You need to use the SDWAN rule manual method to route traffic for certain sources via specific wan interface and can setup perf. sla when it is down it will remove the route via that specific interface

Let us know if this helps.
Salon Raj Joshi
damianhlozano

Thank you sjoshi for your response!

I still do not see how to accomplish this.

I think if I create a rule with manual method, to this specific IP range, to use WAN2, when WAN2 is down, this specific IP range should use the implicit rule, is this correct?

 

Also, it does not matter, but once a Fortinet engineer told me that SLA are just considered in those rules with an "Interface selection strategy" capable to consider WAN SLAs, for example "Lowers Cost (SLA)", this engineer told me that SLA values are not considered on manual rules.

 

Thanks in advance.

Regards,

Damián 

Damián Lozano
Damián Lozano
sjoshi

once the perf sla is down it will remove the route from wan2..now the manual rule itself wont get trigger and will look the below rule

Let us know if this helps.
Salon Raj Joshi
damianhlozano

This is what I meant.

Below rule is the implicit rule, how can I change the implicit rule to only use one SD-WAN member?

 

Thanks in advance.

Regards,

Damián

Damián Lozano
Damián Lozano
sjoshi

Implicit rule cant be made to use only single ISP.

You need to create a new rule for that

Let us know if this helps.
Salon Raj Joshi
damianhlozano

Again, no matter how many rules I create to those IP to use WAN2, if WAN2 is down, all rules to use WAN2 will be not considered and the traffic should use the implicit rule.  I am right?

What we need is that, for example, 172.16.0.50 could use only wan2, and when WAN2 is down, this IP could not reach anything on Internet.

If I have the implicit rule for all other computers, and I create a manual rule for 172.16.0.50 to use WAN2, if WAN2 is down, this rule will not be considered and all traffic comming from this IP should use the implicit rule, Am I right?

 

Thanks in advance.

Regards,

Damián

 

Damián Lozano
Damián Lozano
sjoshi

yes if wan2 is down and perf sla is setup with update static route then it will match the implicit rule and should work

Let us know if this helps.
Salon Raj Joshi
damianhlozano

Hello sjoshi,

 

I think you didnt understand what I need.

I need the following:

* If WAN 2 is working, 172.16.0.50 should use WAN2

* If WAN 2 is not working, 172.16.0.50 should have NOT Internet access

 

Thanks in advance.

Regards,

Damián

Damián Lozano
Damián Lozano
sjoshi

Hi Damián,

 

So your requirement is if wan2 is active then it should go via wan2 using sdwan manual rule but if wan2 is down then the internet for that specific source should not work from the other ISP.

So in that case that would not be possible to block the traffic from the another ISP because once the wan2 is down it will start matching implicit rule and will go out of the other interface and even from firewall policy you would not be able to block it as both the interface will be part of same SDWAN Zone.

 

But one thing you can try is create 2 zone

zone 1:- wan1 as member

zone 2:- wan2 as member

 

In this case please create 2 policy from lan to zone 1 and lan to zone2

If wan2 is down then the traffic will go out of wan1 which is part of zone1 and under the firewall policy lan to zone1 for that specific source you can set the action as deny.

Let us know if this helps.
Salon Raj Joshi
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors