I have created the BDI interfaces on the Cisco SD-WAN routers with VRRP. Fortigate firewalls are working in active passive mode. We have connections to both routers from each firewall. Please suggest the config to follow here on FortiGate so that in case the link to SD-WAN router 1 goes down from FortiGate firewall 1, traffic should go out from SD-WAN router 2 from FortiGate firewall 1 link. Please suggest other options also
Hi team ,
please refer the below document and configure
https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/850547/vrrp
https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-VRRP-configuration-and-debug/ta-...
Thanks for sharing the documentation.
In the snip, we connect to both routers from the active and passive firewall on the same VLAN. meaning, Physical interfaces on firewalls connecting to the router are in the same network. Is there any way, i can add fw ports in same vlan and so both ports become part of same network.
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.