We are considering moving over from the traditional link failover method to using the SD-Wan features of FortiOS 5.6. It can get a complicated when you start throwing in redundant WAN interfaces, redundant IPSEC VPN Tunnels, eBGP, IPv6, etc.
So hopefully this is a simple question. We have a requirement that if the primary WAN link goes down that some of our VLANS do not get any internet. (e.g. complementary wifi, etc) I am able to accomplish this with specific firewall policies to WAN1 and WAN2 interface. However with SD-WAN all policies now go to the new SD-Wan virtual interface.
So how do I accomplish "cutting" off internet access if the primary link fails when using SD-WAN?
-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
FYI - In case anyone else has this question. You can use policy routes to accomplish this.
-DDSkier FCNSA, FCNSP FortiGate 400D, (2) 200D, (12) 100D, (2) 60D
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1670 | |
1082 | |
752 | |
446 | |
226 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.