Hi Folks,
I have 2 WAN connections which I currently use routing policies to send traffic out, I would like to know if it is possible to cascade/overflow traffic from WAN1 to WAN2 when a certain bandwidth is exceeded, for example:
WAN1 hits 10Mbs usage and I would like the "excess" traffic to then use WAN2 until the load is reduced on WAN1 at which point WAN1 should be used again.
I have come across a number of FG docs which allude to the fact this may be possible but if anyone could point me in the right direction I would be grateful.
Thanks
Eddie
Solved! Go to Solution.
ECMP is what you are looking for in this scenario.
Looks like Spillover will do what you want.
Details here:
and
http://cookbook.fortinet.com/multipath-routing-basics/
Thanks,
You don't have to delete the existing WAN ports or anything unless you are wanting to add them to a different zone or something like that.
With the existing policies in place (as long as they mirror each other) you can setup ECMP how you want.
Mike Pruett
Sorry Arcam, I missed the part about spillover. If you just wanted to do dual routes and have it failover when one link fails you are good to go. For the WLLB setup you WILL have to move it over. My apologies. I feel like today is another Monday!
A quick way would be to setup WLLB with two interfaces that are not in use. then back up the config and do a find and replace of the members and the policies to make the new WLLB interface go in place. From there you only have the downtime of restoring the new modified config.
Mike Pruett
ECMP is what you are looking for in this scenario.
Looks like Spillover will do what you want.
Details here:
and
http://cookbook.fortinet.com/multipath-routing-basics/
Thanks,
Thank you, I will give that a go. The only issue is the downtime in setting it up as the current WAN ports need to be deleted along with the policies etc to set it up.
Cheers
Eddie
You don't have to delete the existing WAN ports or anything unless you are wanting to add them to a different zone or something like that.
With the existing policies in place (as long as they mirror each other) you can setup ECMP how you want.
Mike Pruett
Hi Mike,
I thought it had to be done like this: http://cookbook.fortinet.com/redundant-internet-connections/ before I could setup the overflow part?
Sorry Arcam, I missed the part about spillover. If you just wanted to do dual routes and have it failover when one link fails you are good to go. For the WLLB setup you WILL have to move it over. My apologies. I feel like today is another Monday!
A quick way would be to setup WLLB with two interfaces that are not in use. then back up the config and do a find and replace of the members and the policies to make the new WLLB interface go in place. From there you only have the downtime of restoring the new modified config.
Mike Pruett
Thanks Mike, that sounds like a plan :)
I want to try this myself too since I didn't know spillover was available. One thing I want to remind is if you have vpn into/out of the FG, dynamic ones might fail if outgoing interface is different from incoming, then you need to set static routes to one interface for static ones to keep outgoing and incoming interface is the same.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.