Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Load balancing problem

Hi everybody I have problem with Fortinet 300A which has placed in front-end firewall on back-to-back scenario. I want to Load share and load balance two Internet Connection from two different ISPs. The Port-6 is connected to back-end firewall ,port-2 is connected to ISP1 and Port-3 is connected to ISP2 I defined two Static routes (0.0.0.0/0.0.0.0) with the same distance to each Port-2 and Port-3 I have Access policy that allow Internal connection to External connection and defined Server Ping to both ISPs I dont' t have any Policy Route Fault tolerance is correct,it means whenever I unplug one connection, alternate route is used but load balancing doesn' t work this means that forigate uses only its port-2 to route packets in normal time please help me Thanks in Advanced
5 REPLIES 5
UkWizard
New Contributor

Fortinets do not ' load balance' as such, you may have been misled by the sales jargon. Basically, it cannot load-balance, instead, what you can do is tell traffic (using the policy routing) to use particular connections. So you can specify certain matched traffic (which can be matched on any of source ip/dest ip/service) to use what connection you want. So, for example, you could say, if traffic is http traffic, use the backup link. or, if you have multiple internal subnets, you could say internal lan 1 uses the backup link. Therefore the fortinets " load share" NOT " load balance" . See this doc for the official description; [link]http://kc.forticare.com/default.asp?id=376&SID=&Lang=1[/link] Its a shame, but i believe its under development.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

Thank you so much UkWizard So Fortigate can' t Load Balance per session or per packets (like Cisco Routers) Let me ask another question, Do you know how could I configure ' ping server(like fortinet)' on Cisco devices?
Not applicable

AFAIK, Cisco router does not have any load balance ability either per packets or per session. If you are talking about multiple equial cost path over dynamic routing, FortiGate v3.0 MR1 is able to send traffic over multiple pathes.
gili
New Contributor

hi i jusk upgrade my FGT-60 to ver 3.00 how can i config load blalace between two WAN' s ? is there a way that traffic will get out from the least Utilized port ?
http://www.meteorit.co.il
http://www.meteorit.co.il
Not applicable

As someone already stated, you can' t do real load balancing. In an HA cluster, AV traffic is the only thing that is load balanced. There is a command " load balance all" But, it does not work in our scenario. I guess you could try it and see if it works by viewing sessions after that. But,I think there are major issues with this part of the FortiOS. They are reportedly going to be fixed in 2.8 MR12. I' m still waiting for that same fix.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors