Hi Fortinet community
I’m currious to hear if anyone has experience or would share their journey towards SD-WAN / SD-WAN zones from a running production FortiGate.
I’m managing serveral firewall, all currently build with “normal” interface added to zones etc.
FortiOS v6.4.9
FMG v7.0.3
The interfaces and zones are all referencer in many different policies.
I do manage all FortiGates via FortiManager.
I’d like to add the interfaces / VPN-interfaces from zones to SD-WAN zones, to start using some the SD-WAN features i.e performance SLA for best egress port.
Many of our FortiGates have Dual ISP connection (WAN1 + WAN2) and redundante IPSec / ADVPN tunnels and using BGP for dynamic prefix announcements.
However, as I can see - I can’t just move an interface from a zone to a SD-WAN zone, without removing it from the zone first.
Then I have to deal with the change to all the IPv4 policies in regards to source / destination interface, where the SD-WAN needs to replace the old zones.
Has anyone done this in a smart / easy way via FMG?
Can I just clone the policy packet, and replace the zones with the SD-WAN zones and preb the device DB with the new settings as well, and push it all to the gates in one go?
Thanks in advance
Hello Jonas,
Thank you for using the Community Forum.
I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Regards,
Hi, Any info about the above raised questions?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1759 | |
1116 | |
766 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.