One of our remote offices has been having intermittent internet issues (thanks Comcast). From what I have been able to find, by default FortiGates don't do much health monitoring on WAN connections, and that if I want WAN health monitoring I need to configure SD-WAN.
I have never configured SD-WAN before and wanted to avoid any gotchas.
Some of the questions I have about SD-WAN
Yes, SDWAN is the way to go.
Thank you for the quick and thorough response.
The remote office only has 1 internet connection, so no failover is possible, and with that being the case I don't think I have to worry about routes updating.
Do you have any guides you would recommend/link for setting up SD-WAN?
If you only have 1 interface and are just looking to log the link going down, you are probably better off looking at just link monitor then instead of going through the trouble of sdwan.
set it up with "set update-policy-route disable" and this should just log a message when it fails.
@distillednetwork
Thanks for the information, this does seem like a good first step before trying to go headfirst into SD-WAN.
Do you have any recommendations on what I should set the "Set Server" too? In some of the Fortinet examples I have seen Google's DNS being used, but wanted to check if you had any other recommendations? For example, next hop or Cloudflare?
Google DNS is a pretty solid choice, since you're using it just for logging, you can add more than 1 monitor there. You could add Google DNS and use the gateway of your ISP connection. That could help you see when there is a failure, if it's at the first hop or further out on the ISPs network.
User | Count |
---|---|
2619 | |
1390 | |
804 | |
666 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.