Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gquerenghi
New Contributor

Policy routing

I' m sorry if this is a stupid question, I have a fortigate 80b and two isp' s connected to each wan port I' m trying to create a policy route for one ip address' s traffic to be routed through wan2 and the rest of the internal network through wan1 my internal network is 10.30.12.0/255.255.254.0 the device I want to route is 10.30.12.210 I' m not sure what mask should I put to route that single device If I enter 10.30.12.210/255.255.254.0 it changes to 10.30.12.0/255.255.254.0 If I enter 10.30.12.210/255.255.254.255 I get invalid ip/subnet mask also, I have 2 static routes for 0.0.0.0 going through wan1 and wan2, will the policy route have priority over those ones?
3 REPLIES 3
jmac
New Contributor

Policy routes will take precedence over all other routes. First, to send default traffic to wan1, each of the two static routes to 0.0.0.0 should have the same distance setting, but the route to wan1 should have a lower priority value than wan2 (lower numbers equal higher priority). Add a policy route for your source device on the internal network as 10.30.12.210/255.255.255.255 (this subnet mask means use this IP only and not a larger range). Don' t forget separate firewall policies for each interface pair.
gquerenghi
New Contributor

thanks it works fine another question I have a fortigate to fortigate vpn between two offices the vpn is under wan1 interface I backup a nas from officeB to a nas in officeA (which has the 2 isps) is it possible to have the incoming data go through the isp of the wan2 interface?
jmac

You need to create two VPN tunnels, one from office A over wan1 to office B, and another from office A over wan2 to office B. Add static route entries (on both sides) for each tunnel for the remote IPs at the other end, setting equal distance but lower priority value for the primary connection. Add a policy route at the site initiating the backup to force traffic to use the tunnel assigned to the wan2 ISP by assigining source & destination IP/port/protocol as necessary.
Labels
Top Kudoed Authors