Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
flybelgium
New Contributor

LAN users to WAN1 and Wifi to WAN2

Hello,

 

I have a Fortigate 100E and i would like to route internet traffic to 2 differents WAN. Actually, i have made this configuration and... not working :

1. In interfaces, i have my 2 WANS configured with the ISP ip config

2. In Static Routes, i have my 2 WANS configured with the gateway of my ISP. First with distance 10 and WAN 2 with distance 20.

3. In IPV4 Policy i have basicaly 2 policies :

--> 1 All LAN traffic to WAN1 source all - destination all with AV, Web Filter and AppControl and SSL Inspection.

--> 2 LAN Traffic with in source 2 Locales IP only 192.168.100.10 + 192.168.100.11> destination All to WAN 2

At this point all the traffic go to WAN1...

I have made a policy to DENY 192.168.100.10 and 192.168.100.11 to WAN1

At this point, this two ips are not working... no WAN traffic, in traceroute i dont have any responses, local network ok, no outgoing traffic to WAN2 or WAN1.

 

Important, WAN1 traffic go to CISCO Router and WAN2 Traffic is a cable modem in bridged mode. I just would like to route selected IP to WAN2 and the rest to WAN1, like servers to wan1 and users to wan2. Any idea ?

Thanks in advance.

10 REPLIES 10
sw2090
Honored Contributor

Basically:

 

if you set your policies in the order you wrote them down here all traffic will alwys match the first and go to wan1. The second in this case will never ever match since policies are always exempt in fortios.

 

(2) must be the first policy to match those two ip.

(1) comes behind that and matches the rest of the subnet.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Labels
Top Kudoed Authors