Hi all. I am trying to configure a new Fortigate setup, with 2x WANs. I did search before asking you, but I could not figure out how to achieve an Active-Passive scenario. WAN-2 is very unstable, it should be passive and not take any traffic as long as the other WAN-1 is up.
A youtube video instructed
This is not what I want, since traffic is distributed.
I want traffic to flow through WAN-1. When WAN-1 goes down, should be detected, and WAN-2 should take over. But when WAN-1 comes back online, it should take over the traffic again. I am sorry if this has been asked before.
Could you please tell me step-by-step how to achieve this? Thanks in advance. Regards
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If you want to do this with SD-WAN, you can set the implicit policy (at the bottom of SD-WAN Rules) with algorithm: Sessions or Volume, then set the "weight" of unpreferred wan to "0" while the preferred wan has a possitive number, like 10.
With this setting all traffic which doesn't match any explicit rules above goes out only through the preferred wan. Then only in case the preferred wan goes down, the unpreferred wan would be used.
But you probably want to have a way to test the second circuit. So I would create at least one explicit rule like destination 8.8.4.4/protocol number 1(ICMP) toward the unpreferred wan to override the implicit rule.
On the other hand, if you don't want to use SD-WAN, you can set two static default routes to both circuits (you need to disable dynamic gateway if the circuit is DHCP/PPPoE) but set the "priority number" of the unpreferred default route higher like 10 (default is 0), so that only the preferred circuit would be uses for outgoing traffic as long as it's up.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1547 | |
1031 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.