Created on 06-19-2006 04:38 AM
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Created on 06-21-2006 04:36 AM
. Monitoring both WAN interfaces simultaneously. If you need to be able to ping both WAN interfaces in order to demonstrate that the links are up, you will need to set the distance on both default routes to be the same.And from the Admin guide for 3.0 ...
In summary, if a route in the routing table has a lower sequence number than another route to the same destination, the FortiGate unit will choose the route with the lower sequence number before choosing the other route. Because you can use the CLI to specify which sequence numbers or priority field settings to use when defining static routes, routes to the same destination can be prioritized according to their sequence numbers and priority field settings. To prioritize a static route, you must create the route using the config router static CLI command and specify a low sequence number or high priority for the route.In effect monitoring both interfaces with ping does not work. I tried all permutations & combinations of distance & priority. The last route in sequence OR the highest priority route takes precedence. Now the problem is if wan2 has a precedence & if in DNS settings and wan1 isp' s dns server is 1st in the list, the firewall is unable to resolve the domain name & hence the updates fail. Even though the ip of 2nd isp is given in the second dns server field. I have verified this. This creates the problem that in case of link failure of the ISP with higher sequence number, updates are bound to fail. And I think same thing is happening on system restart. Is this a bug or is there a way to resolve this?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.