Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RJ1
New Contributor III

FortiGate Virtual Interfaces Shows as down on the GUI, but in CLI, the interface is UP.

Internet and ADVPN interfaces are virtual on the firewall. When either the ISP or ADVPN goes down, the Firewall marks interfaces as DOWN on the GUI but in CLI, the interface appears up. Any suggestion on same, we are running FortiGate version 7.2.8

SJ
SJ
6 REPLIES 6
kaman
Staff
Staff

Hi RJ1,

As you mentioned that the ISP goes down but still there were active route in the routing table. In FortiGate, the route preference will be first policy route and then SD-WAN routes.

Hence you should have a default route pointing toward the SD-WAN virtual interface this will help to route traffic with other interfaces when one link fails.

Please refer to the below article on how to configure an SD-WAN properly.

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/218559/configuring-the-sd-wa...

For your query make sure:
1. Static route is pointing to SD WAN zone:

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/626338/adding-a-static-route

2. Make sure the Performance SLA has the SD WAN members selected and 'update static route' enabled:

Note: If 'update static route' was disabled under Performance SLA then enabled the 'update static route' and check the routing table.

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/723056/link-monitoring-and-f...

If you have found a solution, please like and accept it to make it easily accessible to others.

Regards,
Aman

RJ1
New Contributor III

Thank you for your reply Aman, the issue is when ISP or ADVPN (Virtual interface) is down, it shows as "DOWN" in GUI but in CLI status is "UP"

SJ
SJ
kaman
Staff
Staff

Hi RJ1,
Can you please share the output of the CLI?
And GUI screenshot 

RJ1
New Contributor III

Unfortunately cannot share the screenshot, as the FWs are in production and the interfaces are UP now, so Once its down again will capture screenshot.

SJ
SJ
kaman
Staff
Staff

Hi RJ1,

If 'update static route' was disabled under Performance SLA then enabled the 'update static route' and check the routing table.

RJ1
New Contributor III

ok will do it and will let you know the output.

SJ
SJ
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors