Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fortinetforumfiokom
New Contributor II

How how can I limit the traffic to only one SD-WAN interface

Hi, 

(Fortigate 201F, 7.4.3)

I have a new SD-WAN setting, and I have an internal e-mail server. How can I limit the email server traffic (SMTP) so that traffic  only goes out through the designated SD-WAN interface. If that interfece go down, I do not want to allow to go this traffic out in other SD-WAN interface. 

A would like to prevent the email traffic to go out from an other public IP.  My current goal is not to configure the mail server (DNS, MX, SPF etc...)

I tried to create an SD-WAN rule (Interface selection strategy = Manual) with the mail server address and SMTP traffic, where I only specify one SD-WAN interface in the interface preferences, but it seems that if I stop this interface, the traffic still starts to go out on the other interface. How can I stop this from happening?

 

Thanks

 

12 REPLIES 12
wagersantonio
New Contributor II

To ensure that email (SMTP) traffic only exits through the designated SD-WAN interface and doesn't failover to another interface, you can use a combination of SD-WAN rules and firewall policies. First, create an SD-WAN rule with the Manual interface selection strategy, specifying the correct SD-WAN interface for your email server’s IP and SMTP traffic. Then, set up a custom firewall policy to match the email server’s traffic and apply a deny rule for other interfaces. Additionally, disable SD-WAN failover for that specific rule by configuring the Failover option to Disable. This will prevent the SMTP traffic from being routed through any other interface if the designated one fails. I did the same practice at http://thevapetown.com/vape-shop-in-islamabad/

sjoshi
Staff
Staff

You can create 2 sdwan zone and place each interface in separate zone and create 2 firewall policy with 2 zone and on the 2nd zone set the action as deny

Let us know if this helps.
Salon Raj Joshi
vbandha
Staff
Staff

Hi @fortinetforumfiokom ,

 

One solution would be to create a policy route for this traffic. 

Policy route has higher priority than SD WAN rule so the traffic would follow the Policy route you create. 

 

https://docs.fortinet.com/document/fortigate/7.6.0/administration-guide/144044/policy-routes

 

Regards,

Varun

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors