Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jtfinley
Contributor

Design thoughts

I have 4 physical locations. 2 Locations are connected via fiber and on same logical network exiting to Internet via (2) EQCost ISP. See simple attached drawing - each color is own subnet. The other locations will be connected soon. I plan on creating a VLAN for the fiber links which will connect into HP Procurve GBICS at each location and utilize the DMZ port at each location for routing. I' d like to create Internet resilience an ISP were to down; the locations could travel across the dark fiber and egress at next hop. Thoughts?
2 REPLIES 2
stencilloart
New Contributor

I' d like to create Internet resilience an ISP were to down; the locations could travel across the dark fiber and egress at next hop.

Toshi_Esumi

If you only care about two ISP redundancy at those three locations where two internet circuits terminate, I would put only those two circuits into an SD-WAN zone and set up an appropriate method to fail-over or load balance.
But if you want to re-route the internet bound traffic via another location when both two circuits go down, you probably need a routing protocol to advertise local subnets to wherever the internet egress at that time, in addition to getting a default route.
SD-WAN member circuits use static default routes so it always wins over the default route advertised over the routing protocol from a neighboring location. Then only when both went down it would "float" up.

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors