Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fred339
Contributor

PING Through an SD-WAN Fortigate with 2 ISPs.

Fortigate 80F 6.4.10 with 2 WAN interfaces into an SD-WAN.

WANs are set up to switch to "secondary" if "primary" is down .. and back to "primary" when it is up.

I want to set up a PC to continuously ping (with a script) and traceroute out through each ISP.  So, a separate target destination for each WAN.

I've not gotten this to work yet.  I've been trying with the FG CLI.

wan1 is primary and active; wan2 is secondary and not active

exec ping-option source [wan2 IP]

exec ping-options interface wan2

But, pings don't work with this....

And, separately, setting traceroute-options

exec traceroute-options source [wan2 IP]

exec traceroute 8.8.8.8

yields the wan2 IP hop and no more....

 

 

Fred Marshall
Fred Marshall
3 REPLIES 3
sidewaysguy14

In general, you should be able to do this by creating the address objects for the computer and public IPs.  Then use SD-WAN rules to manually send the traffic from Computer --> ISP1 destination through WAN1 and Computer --> ISP2 destination through WAN2.  

 

I'd recommend having a look at the Performance SLA documentation, as for the ping check you could configure an SLA monitor for the specific interface and destination. https://docs.fortinet.com/document/fortigate/7.2.2/administration-guide/584396/performance-sla 

Secure all the things!
fred339
Contributor

@sidewaysguy14: Thank you!

Fred Marshall
Fred Marshall
sidewaysguy14

Anytime @fred339  :)

Secure all the things!
Labels
Top Kudoed Authors