- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
FortiGate Virtual Interfaces Shows as down on the GUI, but in CLI, the interface is UP.
Internet and ADVPN interfaces are virtual on the firewall. When either the ISP or ADVPN goes down, the Firewall marks interfaces as DOWN on the GUI but in CLI, the interface appears up. Any suggestion on same, we are running FortiGate version 7.2.8
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi RJ1,
As you mentioned that the ISP goes down but still there were active route in the routing table. In FortiGate, the route preference will be first policy route and then SD-WAN routes.
Hence you should have a default route pointing toward the SD-WAN virtual interface this will help to route traffic with other interfaces when one link fails.
Please refer to the below article on how to configure an SD-WAN properly.
https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/218559/configuring-the-sd-wa...
For your query make sure:
1. Static route is pointing to SD WAN zone:
https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/626338/adding-a-static-route
2. Make sure the Performance SLA has the SD WAN members selected and 'update static route' enabled:
Note: If 'update static route' was disabled under Performance SLA then enabled the 'update static route' and check the routing table.
https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/723056/link-monitoring-and-f...
If you have found a solution, please like and accept it to make it easily accessible to others.
Regards,
Aman
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for your reply Aman, the issue is when ISP or ADVPN (Virtual interface) is down, it shows as "DOWN" in GUI but in CLI status is "UP"
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi RJ1,
Can you please share the output of the CLI?
And GUI screenshot
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unfortunately cannot share the screenshot, as the FWs are in production and the interfaces are UP now, so Once its down again will capture screenshot.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi RJ1,
If 'update static route' was disabled under Performance SLA then enabled the 'update static route' and check the routing table.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ok will do it and will let you know the output.
