Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Bunce
New Contributor

Force Logging traffic out secondary WAN

Hi all, We have a number of remote sites with dual WAN connections and need to carefully manage bandwidth due to quotas and excess charges. These tails are Satellite or 3G connections and suffer from periodic outages. The sites are setup with an active default route on each WAN tail - with same distance but differing priorities, as per the following article: Tech Note This allows us to confgure failover VPN tunnels when the primary drops, as well as sending high traffic workloads out the secondary (unlimited) tail using policy routes. We need to send our logging traffic to the FAZ out via the secondary WAN (ie the one with the higher priority) but don' t seem to be having much luck.. I' ve configured the source-ip setting of config log analyzer setting, to the external IP of the WAN2 interface but a sniff still shows it going our the primary. Using the IPSEC tunnel setting of the config log analyzer settings also seems to create the tunnel, but again, via the primary WAN.. Policy routes don' t seem to have much effect so I' m wondering if there is some other type of configuration I' m missing? Thanks in advance
0 REPLIES 0
Labels
Top Kudoed Authors