Hi all, I'm planning to do SDWAN with my current setup, but I've to admit that my setup might not be optimal. Currently the setup is, LAN --- HQ FG --(Single WAN)-- LB (3 WANs) -- Internet -- (Single WAN) -- Branch FG.
My plan, was to build 3 IPsec VPN tunnels, and implement SDWAN over it. So the best performance tunnel will be selected automatically. I tried a few methods but I failed,
1. Secondary IP with different segment on HQ FG, configure Port Forward (or VIP) on LB, each WAN maps to one specific IP.
2. Loopback interface with different segment on HQ FG, configure Port Forward (or VIP) on LB, each WAN maps to one specific IP.
3. Peer ID, Local ID.
4. Network-overlag, network-id.
I'd like to seek for help on how can I achieve my plan with SDWAN. Appreciate any help, and thanks in advance!
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
I will answer to the question: how to establish multiple IPsec VPN tunnels via a single WAN interface on FortiGate, you can follow these steps:
User | Count |
---|---|
2250 | |
1223 | |
772 | |
451 | |
366 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.