Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Maerre
Contributor II

Dual WAN SD-WAN configuration with service exposure on both links

Hi,

I have a customer who currently uses two WAN connections: a primary one (Swisscom) and a secondary one (Horizon).
Some services are also exposed only on the primary WAN.
They asked if it’s possible to combine the two connections so that, in case the primary wan becomes saturated, part of the new traffic is automatically redirected to the secondary wan.
Additionally, they would like to expose services simultaneously on both WANs.

From what I understand, the only way to address the first issue is to configure an SD-WAN, adding both WANs to the Virtual Link Zone, including this zone in all policies and static routes, and then creating an SLA monitor.

As for the second point, how could that be handled?
Would it be feasible to create a virtual VIP address?

Thanks,
Cheers

3 REPLIES 3
funkylicious
SuperUser
SuperUser

hi,

SD-WAN controls the egress/outbound traffic, not the ingress/inbound traffic.

they should expose the services via both public IP's on the FGT/SDWAN and create a redundancy logic at the DNS level with ttl or something similar

"jack of all trades, master of none"
"jack of all trades, master of none"
Maerre

Hi @funkylicious 
you mean create a redundancy logic at DNS level on FGT or on their DNS?

funkylicious

the public dns zone which resolves the hostname to ip, not locally on FGT.

"jack of all trades, master of none"
"jack of all trades, master of none"
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors