Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Multiple Gateways

We have just upgraded to Version 2.8 of the Fortigate OS. We used to be able to have 2 gateways setup per static route as we have both a leased line and ADSL connection running at the same time. This feature no longer seems to be available, as we would like to do source routing and our web browsing traffic out our ADSL line. Can this still be done?
42 REPLIES 42

Finally I have got policy routing working. You have to: - have a ping server configured on the interface where you want to perform the policy routing. - configure your policy routing using either the GUI or the CLI Seems to be working fine here for me!
UkWizard
New Contributor

that kinda makes sense, good job ..
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Not applicable

I' ve just found that if you route all your browsing traffic out of another port, it stops you from accessing any sites that you host in your DMZ. I' m now waiting for Fortinet to come back to me!
UkWizard
New Contributor

Thats probably because the outbound traffic would be natted behind the other PORTS ext IP.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Johan_Lysen
New Contributor

Hmm, i also tried the " ping-server" AND routing solution u describe, but still have some issues with that config. Have u setup an environment where u have a both a " primary" and a " secondary" internet access (as in the version 2.5 software where u had dual default gateways) and tried to failover and fallback between those. When i tested that solution i got problems with all the " current sessions" , whilest all the " new session" works just fine. If i have a protocol with a high session timeout, say RDP(3389/tcp) and a session timeout of 4 hours, i have to wait 4 hours to failover all the current session. In other words - it doesn' t work... Do u see the same problem in your solution or ?! /Johan

Johan Lysen Consulting AB Johan Lysen, Johan@Lysen.nu Byvagen 87, 832 46 FROSON Mobile: +46 70 6009221

Johan Lysen Consulting AB Johan Lysen, Johan@Lysen.nu Byvagen 87, 832 46 FROSON Mobile: +46 70 6009221
Johan_Lysen

Summary: In version 2.5 " Multiple Gateways / Dual ISP" is working OK In version 2.8 it´s not. After a failover or fallback: All new sessions are working ok All old sessions stops working for 30-120 seconds

Johan Lysen Consulting AB Johan Lysen, Johan@Lysen.nu Byvagen 87, 832 46 FROSON Mobile: +46 70 6009221

Johan Lysen Consulting AB Johan Lysen, Johan@Lysen.nu Byvagen 87, 832 46 FROSON Mobile: +46 70 6009221

hi " In version 2.5 " Multiple Gateways / Dual ISP" is working OK In version 2.8 it´s not. " just today I' ve upgraded my FG60 to 2.80MR3 then downgraded to 2.50MR9 caused by your same problem. I worked around sometime without success.
Johan_Lysen
New Contributor

Hi It´s nice to see that i´m not alone with this problem as i first thought... In my environment we decided that we can live with this bug, at least it does a failover in time i u just wait... (and get some extra gray hair during the grace period) The problem is also verified by the distributer in Sweden, Smartsec. I have a ticket at the Fortigate support about this, but i´m sorry to say there is no answer at all from them. /Johan

Johan Lysen Consulting AB Johan Lysen, Johan@Lysen.nu Byvagen 87, 832 46 FROSON Mobile: +46 70 6009221

Johan Lysen Consulting AB Johan Lysen, Johan@Lysen.nu Byvagen 87, 832 46 FROSON Mobile: +46 70 6009221
Johan_Lysen

I´ve closed the ticket with the support, there is no straight answer there...

Johan Lysen Consulting AB Johan Lysen, Johan@Lysen.nu Byvagen 87, 832 46 FROSON Mobile: +46 70 6009221

Johan Lysen Consulting AB Johan Lysen, Johan@Lysen.nu Byvagen 87, 832 46 FROSON Mobile: +46 70 6009221
UkWizard
New Contributor

Raise a new post colm and state your config and what you are trying to achieve, and we can then see if we can help.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors