Hello there,
We have two WANs in place. We just upgraded our Internet for WAN2 today. We are going to be losing WAN1 in a few days and replacing it with another WAN1. However, WAN2 is meant to become the new primary. What steps should I take to ensure that the Fortigate Firewall does this conversion properly? Do I need to take the Ethernet cables and swap them or is there a way to just switch the WANs in the system?
You needed to troubleshoot when the problem was happening. Now you need to take the wan2 down to simulate then check routing why it doesn't go to wan1. I don't remember if I mentioned this before any more since it's been quite some time but make sure you have
config system global set snat-route-change enable (by default it's disabled) end
configured in CLI. Otherwise, on-going SNAT sessions won't fail over.
Actually the easiest way to troubleshoot is calling in to TAC if you have control to re-create the situation.
Toshi
Wait. Did you swap the admin distance between wan1 and wan2? Priviously wan1 was primary and admin distance was 5 while wan2 had 10. Since wan2 is now primary you need to swap them.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.