We have a Fortigate 100D firewall (Fortios 5.2.x) with Dual WAN (WAN1 and WAN2 interfaces) connectivity to 2 different ISP’s. It is acting as active/passive. WAN1 is the primary WAN link (distance 10) WAN2 is our failover link (distance 20)
All is working well but we want to monitor our WAN2 link with third-party monitoring software (Paessler PRTG) Because WAN2 is passive, ICMP ping doesn’t work. This would be the simplest method for proactively monitoring the WAN2 link with other monitoring software. I want to know if there are other methods before considering FortiAnalyzer.
Is it possible to enable ICMP ping to a passive WAN2 link? Are there other methods to achieve proactive alerting (e.g. e-mail, snmp) when a passive WAN2 interface fails?
What I’ve learned so far:
[ul]Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
hi,
just some thoughts:
- for a WAN interface you need a default route. Use 2 default routes with same distance but higher priority on the backup WAN. ("priority" in FOS means "cost".) This way, both routes are active in the Routing monitor and should enable reply traffic.
That is, if a passive cluster member answers to incoming traffic at all. This might well not be the case!
- regarding SNMP
how do you know that the slave unit logs an event in case it's WAN link goes down? Do you access the slave via it's mgmt interface? If so, and this is preferable, it could be possible to enable SNMP on that mgmt interface and to receive a trap. (I know, a lot of "if"s).
hi,
just some thoughts:
- for a WAN interface you need a default route. Use 2 default routes with same distance but higher priority on the backup WAN. ("priority" in FOS means "cost".) This way, both routes are active in the Routing monitor and should enable reply traffic.
That is, if a passive cluster member answers to incoming traffic at all. This might well not be the case!
- regarding SNMP
how do you know that the slave unit logs an event in case it's WAN link goes down? Do you access the slave via it's mgmt interface? If so, and this is preferable, it could be possible to enable SNMP on that mgmt interface and to receive a trap. (I know, a lot of "if"s).
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.