Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tpfannes
New Contributor

Multiple ISP' s

I have a FG unit with two ISP connections. I would like to route customer subnets out one connection and internal subnets out another. I set up a default route for one link and another default route costed out a little higher for the other. I create a policy based route that says if your source IP is CUSTOMER then this is your next hop. Everything works great, my problem is if the ISP my customer is connected to fails it doesn' t failover to the backup link. If the interface is down shouldn' t the policy based routes I created become null? I looked at some ECMP documentation but that seems to rely on different metrics for load-balancing, I need Customer subnets/VLAN' s to go to AT&T and internal to go to 123.net (and both to failover in the event of link failure). As always, any ideas are appreciated. Thanks, Tim
2 REPLIES 2
dlambert88
New Contributor

123Net... sounds like you are in Michigan! Anyway you will need to use policy based routing. The command will have to be done in the CLI depending on your FortiOS version. http://docs.fortinet.com/fgt/handbook/50/fortigate-advanced-routing-50.pdf PG. 23 This does not show CLI, but that can be easily implemented using CONF ROUTER POLICY command.
dlambert88
New Contributor

To failover you will need to use firewall policies with two default routes with different priorities, but same distance. You will also need to implement GWDETECT. If you would like me to do either configuration I will be more than happy to help.
Labels
Top Kudoed Authors