Can we setup interface monitoring so that when ISP is down, then default route to that ISP is withdrawn as well as the LAN side interface is shutdown, so that downstream router / core switch that runs dynamic routing with firewall stops receiving default route from this firewall and thus start using the second one? My understanding is that the cascade interface refers to the source interface, and we don't want firewall outside interface to be shutdown, but the inside interface should be, and so I am assuming srcintf can be any interface that we choose.
And we dont want LAN interface to be periodically brought up to attempt health checks, as that will cause wrong default route to be sent to the core switch. LAN interface should only come up when link monitor declare health of ISP to be good.
config system link-monitor
set srcintf LAN
set gateway-ip <<ISP1GWaddress>>
set server 220.127.116.11 18.104.22.168
set protocol ping
set update-cascade-interface disable
set update-static-route disable
If the link monitor removes the route from the routing table it shouldn't be advertised to the downstream router anymore. Give us some more details to help you out, are you using to WAN interfaces for two ISPs? Which routing protocol is in use?
And how would it help if the LAN interface is shut down, that doesn't make sense? Are you using adynamic routing protocol on the core router or just link monitoring?
Thanks for looking into this. I will be running dynamic routing (eBGP) on the lan side with mpls service provider. If upstream isp is down, then sure health monitoring or link monitoring, will withdraw the static route towards ISP, but I want that to trigger a shutdown of LAN interface for quick removal of BGP peering with mpls router. I have other circuits and firewalls, and other sites that will then be preferred for routing traffic thru those circuits / sites.
So my question would have been better paraphrased if link monitoring can shutdown a defined interface(s) other than the one thru which link monitoring probes are being sent.
Thanks so much.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.