Hi,
Good day everyone.
I would like to seek your assistance as networking is the least of my professional skills :(
Currently, I need to transition the current Internet Line from existing different ISP to another one for one of our remote office but at the same time, let the other old Internet Connectivity up for the time-being.
The old Internet Line (A) is connected to WAN1 of the firewall, and has existing site to site VPN.
The new Internet Line (B) is connected to WAN2 of the firewall. The Internet Line (B) connection has it's own router and the PublicIP is NAT'ed to 192.168.1.2 - connected to WAN2 which now has 192.168.1.3 IP.
My question is, what is the best approach for this? I would like to set-up WAN2 (Line B) as the main line and also set-up site-to-site VPN but at the same time, retain the existing line A as the backup temporarily in case for 2 months before totally discontinuing it if all works well. ...
How can I do this?
Thank you!!!
FortiGate
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
For simple setup, you can achieve this by configure ECMP routes.
Mean both WAN1 and WAN2 will have same distance value set, but WAN1 will have higher priority value set.
The link with higher priority value will be less preferred and stay as standby link.
If you need redundancy for VPN as well, you can configure monitor VPN2 for the VPN configured under WAN1.
In case VPN2 under WAN2 failed, then WAN1 VPN1 will come up.
Reference document:
For Dual WAN:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Redundant-Internet-connection-without-load...
Thanks.
annother solution would be to use sdwan. Add both WAN to the default Zone and maybe create an sdwan rule to maintain which wan to use when - or use the implicite loadbalancing rule.
Attach some health check probably.
Then use the sdwan interface instead of wan1/wan2 in your policies.
And have one default route pointing to sdwan.
SDWAN will do the rest for you. It will detect if one wan is not available and take it out of service and also bring it back in once it becomes available again.
Might just be a bunch of work to change all policies. Maybe goes the fastest if you pull a unencrypted backup from your FGT and edit that and do a search and replace and the sdwan config and then restore it.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1661 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.