Hi everyone,
Can we setup interface monitoring so that when ISP is down, then default route to that ISP is withdrawn as well as the LAN side interface is shutdown, so that downstream router / core switch that runs dynamic routing with firewall stops receiving default route from this firewall and thus start using the second one? My understanding is that the cascade interface refers to the source interface, and we don't want firewall outside interface to be shutdown, but the inside interface should be, and so I am assuming srcintf can be any interface that we choose.
And we dont want LAN interface to be periodically brought up to attempt health checks, as that will cause wrong default route to be sent to the core switch. LAN interface should only come up when link monitor declare health of ISP to be good.
Something like:
config system link-monitor edit "ISP1monitor" set srcintf LAN set gateway-ip <<ISP1GWaddress>> set server 8.8.8.8 4.2.2.2 set protocol ping set update-cascade-interface disable set update-static-route disable
next
end
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello everyone,
Am I asking too hard of questions here? None of my post has been answered in over two weeks now. Can someone please advise me on this?
Thanks
If the link monitor removes the route from the routing table it shouldn't be advertised to the downstream router anymore. Give us some more details to help you out, are you using to WAN interfaces for two ISPs? Which routing protocol is in use?
And how would it help if the LAN interface is shut down, that doesn't make sense? Are you using adynamic routing protocol on the core router or just link monitoring?
Please see this article on configuring a cascade interface:
https://kb.fortinet.com/kb/documentLink.do?externalID=FD44679
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.