Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
haris_khan
New Contributor

Fortigate with dual ISP

Hi everybody , I have been configuring forigate 100d with dual ISP,i have 3 zones that include inside,outside and DMZ and two internet connections terminated on 100d,i want to route internal zone traffic through ISP1 and DMZ traffic through ISP2 ,can somebody guide me how to perform configure this.
Haris Khan
Haris Khan
6 REPLIES 6
Fullmoon
Contributor III

assuming your internet is working fine, you can bend traffic by means of Policy Based Routing or PBR , wherein Internal Network will use WAN1 and DMZ network will use WAN2

Fortigate Newbie

Fortigate Newbie
haris_khan
New Contributor

Thanks for the reply.Let me try and check.
Haris Khan
Haris Khan
lightmoon1992
New Contributor

Check this link as it clarifies more about the different design scenarios: [link=]http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=10376&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=62568875&stateId=0%200%2062570327[/link]

Mohammad Al-Zard

 

Mohammad Al-Zard
emnoc
Esteemed Contributor III

If you ISP give you subnet for the DMZ, you could build vips within that space and all traffic will exit via that vip and subnet range if you place static or PBR route for the services/protocols your are running in the dmz.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Istvan_Takacs_FTNT

I guess you are BGP peering with your 2 ISPs and you are advertising your range upstream via the active/primary link. I think in that case policy routing to force some of the traffic to the " standby" would create asymmetric routing issue and your Fortigate will drop the response coming back via the primary ISP. What I think would help to have 2 different public IP/subnet assigned to the 2 internal network and advertise 1 via ISP1 and 2 via ISP2. Than all the traffic would go back and forth via the same link. It doesn' t seem to be a Fortigate more of a network configuration problem. Interested to see your solution, please post it once you figured how else to do it.
MikePruett
Valued Contributor

WAN1 isp 1 WAN 2 isp 2 0.0.0.0 from inside to wan1 route dmz > wan 2 route...
Mike Pruett Fortinet GURU | Fortinet Training Videos
Labels
Top Kudoed Authors