I know from this post:
That there is no explicit command or checkbox to turn on SD-WAN.
Rather SD-WAN action/behaviour is enacted when the various components e.g. SD-WAN zones, rules etc are configured.
Is it true to say then that unless an SD-WAN rule is configured (in addition to the implicit rule that is always present) there is no SD-WAN action or activity? Without at least one properly configured SD-WAN rule all traffic is directed by the routing table (assuming no policy routing is configured)?
Thanks.....
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
No need to add extra SD-WAN rule to activate SD-WAN, implicit rule will do the job.
Don't forget to add:
@AEK thanks for reply
"No need to add extra SD-WAN rule to activate SD-WAN, implicit rule will do the job."
So SD-WAN can in fact be active, overriding the routing table with only the implicit rule in place?
Hi @slouw
SD-WAN rules define specific policy routing options to route traffic to an SD-WAN member. When no explicit SD-WAN rules are defined, or if none of the rules are matched, then the default implicit rule is used.
Please follow the doc for more details - https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/216765/implicit-rule
Best regards,
Erlin
Thanks @esalija
"When no explicit SD-WAN rules are defined, or if none of the rules are matched, then the default implicit rule is used."
On a production site I am examining I have only the implicit rule as shown.
I was assuming that this rule does nothing and that all forwarding decisions are a function of the routing table.
What in fact does the implicit rule do exactly?
Thanks again
Hi @slouw,
Consider SD-WAN to be enabled to work properly when:
1. You added one or more wan interfaces to an SDWAN zone.
2. Your default route is pointing to an SDWAN zone.
3. Your outbound policies are pointing to an SDWAN zone as outgoing interface and vice versa.
SDWAN rules and performance SLA are optional.
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.