Hi,
I have a customer who currently uses two WAN connections: a primary one (Swisscom) and a secondary one (Horizon).
Some services are also exposed only on the primary WAN.
They asked if it’s possible to combine the two connections so that, in case the primary wan becomes saturated, part of the new traffic is automatically redirected to the secondary wan.
Additionally, they would like to expose services simultaneously on both WANs.
From what I understand, the only way to address the first issue is to configure an SD-WAN, adding both WANs to the Virtual Link Zone, including this zone in all policies and static routes, and then creating an SLA monitor.
As for the second point, how could that be handled?
Would it be feasible to create a virtual VIP address?
Thanks,
Cheers
hi,
SD-WAN controls the egress/outbound traffic, not the ingress/inbound traffic.
they should expose the services via both public IP's on the FGT/SDWAN and create a redundancy logic at the DNS level with ttl or something similar
Hi @funkylicious
you mean create a redundancy logic at DNS level on FGT or on their DNS?
the public dns zone which resolves the hostname to ip, not locally on FGT.
| User | Count |
|---|---|
| 2686 | |
| 1412 | |
| 810 | |
| 704 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.