I have 2 internet line that use dedicated IP address connect to the fortigate 600C.
As default when user using internet it will use A internet line, how to change B internet as default.
I found similar topic (https://forum.fortinet.com/tm.aspx?m=55676) while creating this post but I did not understand what the thread is talking about.
Please help to guide how to do it because I really new and don`t have any idea how to do it.
Thanks.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Simply create a second static route for line B with a distance and priority lower than the route of line A. Then create a policy to allow internal traffic to the secondary WAN.
This procedure allows you to define your default B line. If you want to load balance or other, you will need to make other changes.
BR
Bubu
Bubu
I'm assuming a policy or a set of policies is allowing internet access via both interfaces. Then it's about the default route both interfaces have. Currently a default route toward A internet line is wining. Then do you have two static default routes configured in different costs? Or FG600C is pulling DHCP/pppoe default routes from both internet circuits but different distances are set in interface config?
Check interface config with in CLI:
config sys int
show
then if it's not pulling, check static routes
config router static
show
You need to flip the config between A side and B side whatever you have now.
Hi Bubu, I have tested your method and manage to change B line as default but however after that our 3 branches the tunneling to HQ is down, Others 3 is ok.
what I do was login to fortigate --> router --> static routes --> edit static routes B line (Distance = 3 Priority = 3)
Why other 3 branches down ? Is there any settings that I miss?
===========================================================================
Hi Toshi
* I'm assuming a policy or a set of policies is allowing internet access via both interfaces - Yes
* Below part I not sure and tried your suggestion to check via CLI and there is lot of info and I`m lost while looking for the right info
Currently a default route toward A internet line is wining. Then do you have two static default routes configured in different costs? Or FG600C is pulling DHCP/pppoe default routes from both internet circuits but different distances are set in interface config?
shahruddin wrote:Hi Bubu, I have tested your method and manage to change B line as default but however after that our 3 branches the tunneling to HQ is down, Others 3 is ok.
what I do was login to fortigate --> router --> static routes --> edit static routes B line (Distance = 3 Priority = 3)
Why other 3 branches down ? Is there any settings that I miss?
Regarding VPN tunnels, what do you have as configuration "policy based or route based"? Can you please forward us all active routes?
get router info routing-table all
Thanks
Bubu
Bubu
My advice to you: Leave default VPNs at distance 10 priority 0 Line B in distance 20 priority 0 Line A in distance 20 priority 10
Bubu
So you're using two default static routes on two ppp interfaces w/ priority 17 on the second one. You just need to flip them to use Line B. Or just use Bubu's suggestion.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1547 | |
1031 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.