Hi all,
I have 3 WANs, 2 local network VLANs (LAN-Office, LAN-Server (server1, server2)).
I've already configured like below:
[ul]
The issue is:
[ul]Please note that in both scenarios, I always keep enabling the Firewall Policy (IPv4 Policy) that allow LAN-Office to access LAN-Server (server1 & server2).
How can I fix the issue of pinging between LAN-Office and LAN-Server in the scenario2?
Thank you.
If I disable those port of WAN2 and WAN3 (red box), only enable WAN1 (green box) And also disable the Policy Route here (red box)
And keep the Firewall Policy as the image, the LAN-Office can ping the LAN-Server (server1 & server2).
If I re-enable the policy that disabled in the images above, then the LAN-Office can not ping the LAN-Server (server1 & server2)
My target is: LAN-Office is on WAN1, LAN-Server (server1 is on WAN2, server2 is on WAN3), and the LAN-Office can ping the LAN-Server (server1 and server2).
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I can't tell for sure since I almost never use policy routes, other than SD-WAN. But the first policy route LAN-Office -> WAN1 for all (0/0) must be taking away traffce to server interfaces. To test it, just disable only that policy route to see if you can ping the server.
Then if that's the case set the priority number on the default route toward WAN2 and WAN3 lower so that WAN1 has the lowest number (default=0) so that LAN-Office traffic takes that default route and remove the first policy route.
Policy routes are sticky. Regardless the interface is up or down, they're always evaluated before looking up the routing table. Then if the destination is "all" 0/0, it would take all traffic away. I think SD-WAN's rules (=policy routes) works a little differently thus always works better for most situations.
Do you have Static routes set with the same Distance for each WAN connection?
Make sure your primary WAN connection has the lowest priority EG, 0 and then your other wan connections are 1 or higher.
You'll then want to enable advanced routing under the Settings / Features.
Then program Policy routes to specify server1 as the source and forward traffic to proper WAN port. Make sure you use the gateway IP for the WAN connection that your using.
https://kb.fortinet.com/kb/documentLink.do?externalID=FD46603
If you need to set up any incoming traffic you can setup VIP's (Virtual IP's)
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.