Hello team,
We have 2 ISPs, connected to WAN1 and WAN2.
These WANs are in a SD-WAN with just the implicit rule, as "Spillover", with WAN1 as primary.
About 2 weeks ago, I took 2 of defaults "Performance SLAs", and added both WANs as participants:
These Performance SLAs, are: "Default_DNS" and "Default_Gmail"
Both performance SLA has:
Check interval: 1000 ms
Failures before inactive: 5
Restore link after: 10
IMHO, if WAN1 has a failure, after 5 seconds, everyone should use WAN2. In this case, what event should be logged in the Fortigate?
How can I search for this?
I see events like the following, but no one tells me that a WAN was failing,
* Member status changed. Member in sla.
* Number of pass member changed.
Also, all the events, are for "Default_DNS", no events for "Default_Gmail"
Thanks in advance.
Regards,
Damián
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @damianhlozano ,
Thank you for contacting the Fortinet Forum portal.
-In the event logs it shows only the switch of sla members and for additional logs, you can enable a few settings to verify, You can verify and monitor from sla packet loss on sd-wan GUI as in the below article to monitor the latency, jitter, and packet loss for each sd-wan member:
Best regards,
Manasa.
If you feel the above steps helped resolve the issue, mark the reply as solved so that other customers can get it easily while searching for similar scenarios.
Hello damianhlozano,
Are you using SDWAN or Link-monitor to test for link failure? If it is SDWAN I believe there is a event log called, "SDWAN SLA status warning". You can create an automation stitch based on this event log trigger to send you an email.
Hello Anthony!
This is SDWAN.
There is no event log called "SDWAN SLA status warning"
When creating a stitch, appear the following:
* SDWAN SLA information
* SDWAN SLA information warning
* SDWAN SLA notification
Hello @damianhlozano
The logs you mentioned would be the ones you check:
* Member status changed. Member in sla.
* Number of pass member changed.
You will see Member in SLA and Member out of SLA when their status changes.
It will show you based on member ID and you can check which WAN has the mentioned member ID:
Regards,
Varun
Hello everyone!!
Thank you for your answers!!!
Here, he said:
set sla-fail-log-period <x>
set sla-pass-log-period <y>
FortiGate will keep the logs for 10 minutes. For longer retention, we should have an external storage like FortiAnalyzer.
Related to this, I have 2 more questions:
* For example, If I configure "set sla-fail-log-period 30", this means that if WAN1 is failing, while the status does not change, a log should be record, each 30 seconds, right?
* Is there a way to keep more than 10 minutes without FortiAnalyzer?
Thanks.
Regards,
Damián
Hello @damianhlozano,
* For example, If I configure "set sla-fail-log-period 30", this means that if WAN1 is failing, while the status does not change, a log should be record, each 30 seconds, right?
That's correct
* Is there a way to keep more than 10 minutes without FortiAnalyzer?
Without external logging logs will be retained on memory/disk and will rollover based on the space available
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.