Hi Guys,
Apologies if this has been asked before - I'm new to the forum and to Fortinet.
We currently have 2 individual networks connected to separate ISPs and we use a Fortigate 600c firewall in each network.
I need each network to be able to use the other link as a back up route to the internet should it's primary ISP connection fail.
I'd like to know the simplest configuration for this - My initial thought is to set up a second static route with a higher distance between the WAN 2 ports on each firewall? Traffic from each network needs to be isolated but still be able to access the internet when the primary ISP fails.
Any help/advice would be appreciated.
Thanks
A link failure is logged as a System Event (level "alert"). You could set up the admin email feature to get notified of "alert" or "critical" events.
SNMP trap is your second option, the way the bulk of network devices are monitored or "alerting" their admin.
Pulling the cable is only half smart. Link failure will always be noticed (by observing the link status of the interface) by a FGT cluster. What the (invaluable) ping server feature gives you is detection of connectivity failures further up the stream, beyond the first router or switch.
You have many choices
1: use the 2nd wan port as your earlier thoughts and adjust the distance & use dead gateway detect
2: combine both units to to be a vdom cluster ( this would give you redundancy also btw )
3: place a static route thru the other unit to reach the other ISP ( this would generate more fw-policies to manage probably not ideal )
PCNSE
NSE
StrongSwan
two static default routes through your wan interfaces with the minial distance to the primary ISP and higher distance on the another route.
Configure policies LAN->WAN1 and LAN->WAN2 like you desire, or create a zone interface to avoid make a lot of policies.
Greetings.
Hi Chris
Think the easiest thing for you to do on this would be to setup an interface on each firewall with a private point to point network /30
Setup routes and policies as need to give i each network access to the others internet connection.
you will also want to setup link heath checks to monitor the the internet links if you want automatic fail over to the back up link
Regards
how do i do this on 5.4.1 firmware? i can not find the "Router > Static > Settings"
please help, feeling "lost" with all the changes in 5.4 :\
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1748 | |
1114 | |
765 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.