- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Monitoring from FortiGate
Short version of the story, I've got an external SDWAN provider but traffic through the SDWAN provider is doubling my ping latency. The provider says it's a routing issue that's outside of their control and they've submitted a ticket but if or when their provider supplies a solution is a question.
In my Fortinet, I can set the ping source as my WAN2 interface (that's where the SDWAN solution is plugged in) and manually run a ping from there. However, I'm wondering if there is some way to track this in a more automated way from the FW itself? I'm thinking perhaps through some kind of automation stich but I'm not sure if it's really possible or not.
- Labels:
-
Automation
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
what exactly do you want to automate/keep track of ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Going through WAN1, I get a ping time of about 245ms. Going through WAN2 it's about 490ms. What I want to do is ping through WAN2 every so often (perhaps once every hour) and track if that ping time drops to something more reasonable.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can configure sdwan performance sla health-checks: https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/867342/performance-sla-overv...
At its most basic, Performance SLA health-check continuously pings a specified server to check whether the connection between the Fortigate and the server is Up or not. Typically, public dns servers such as 8.8.8.8 or 1.1.1.1 are used for this.
You can then configure an automation stitch to send you an alert when sdwan flags a failure in the health-checks. Kindly refer to this kb for an example on how to configure automation stitches: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Automation-Stitch-to-shutdown-wan-interfac...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is NOT fortinet SDWAN. This is an external provider.
