Hy,
I have setup SD-WAN on my Fortigate 80E (6.2.0 version).
I have two WAN with gateway and same cost and on implicit rule I setup Spillover.
My WAN1 have 30/30Mbps, WAN2 50/4Mbps.
I want put all my FTP traffic over WAN1 and when I create SD-WAN rule (source all, destination application (all with FTP), manual outgoing interface WAN1) it wont work thought WAN1. But when i put (source all, destination all on port range 21, manual outgoing interface WAN1) it works fine.
Is there some problem with Fortigate build In service?
Hi Mjozo8,
Thank you for the message.
1, When you using application in SD-WAN service rules, you need enable application-control in firewall policy as following:
config firewall policy edit 1 set utm-status enable set application-list "g-default" end
2, Then the SD-WAN service rule will check the traffic and look for the application. for the 1st occurrence of the traffic, it may use implicit rule to forward. the 2nd time, same traffic come, it will use the configured service rule. you can use the following command to check which IPs the SD-WAN has learnt for application-control.
diagnose sys virtual-wan-link internet-service-app-ctrl-list
Hope this answer can help you fix the problem, Stephen
User | Count |
---|---|
2046 | |
1169 | |
770 | |
448 | |
339 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.