Dear all,
Currently I use Microsoft Services as Destination of Static Route over WAN1, then use link-monitor for WAN1. I wonder whether this Route will be deletet from Policy Route when the link-monitor fail?
Can anybody help me clarify this?
Thank you!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I think only static routes toward wan1 would be removed if you monitor wan1. I don't think it would remove any policy routes, which are very sticky.
toshiesumi wrote:Thank you Toshi. So, do you know any way to fall back Microsoft traffic to WAN2 automatically in case WAN1 lost its connnection?I think only static routes toward wan1 would be removed if you monitor wan1. I don't think it would remove any policy routes, which are very sticky.
I am thinking about a script that ssh to Fortigate to disable those static routes.
I'm a little bit confused...are you using a policy route to send Microsoft traffic to wan1 or a static route? Those are very different things with different answers as to how to configure it for failover.
You may need some combination of things in fact to get failover to work right, but understanding what you're starting with better would help me. I have a somewhat similar situation except I'm not actually using link-monitor as I'm doing BGP. The failover concept should be similar though.
I have done a test and confirm that when link-monitor is failed:
- The static route will be removed from routing table.
- The policy route (include static route with internet services as destination) will be changed to disable, check by diag firewall proute list in CLI
@lobstercreed: I use static route with Internet Services as Destination (from firmware 5.6 and later). It can be configured in Static Routes Menu but actually, it's a policy route.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1731 | |
1098 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.