Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RolandBaumgaertner72
New Contributor II

Problems accesing more and more URLs because of SD WAN

Hi,

 

we have a FG100F cluster and are using 3 x WANs to balance our traffic with SD WAN. This configuration is like at least 4 years old and it worked fine but now we get more and more user problems accessing different URLs (e.g ariba.com from SAP) and at the end we have to put more and more adresses in another SD WAN Rule to access only with WAN A. We have now like 10 URLs como exception and I am worried that we are getting more and more.

 

Is there any way to change or adapt the SD Wan for this problems?

 

Thanks!

14 REPLIES 14
akristof
Staff
Staff

Hello,

Just to check, please make sure that FortiGate has access to DNS and FortiGuard. Sometimes, if you have ISP specific DNS, if it goes via another ISP, DNS might fail. Please check this article, check especially fortiguard and dns section:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Functionality-of-set-interface-select-meth...

Adrian
RolandBaumgaertner72
New Contributor II

No we still have the problem, also we got 2 new pages yesterday which we had to include in an exception. I dont know if they are all government sites but it seems that lately they activated this kind of protection to check the source IP.

 

We still have to check the option in SD WAN > Max Bandwith and Source Destination if this will help us.

 

Thanks

gfleming

It will absolutely help you. The problem is today clients are being load balanced across all your WAN links even for the same connections to the same server and the servers are getting upset becuase the source IP keeps changing for the session.

Cheers,
Graham
RolandBaumgaertner72

Hi,

 

but how can I configure a basic rule like my "balancing rule" for most of my traffic with source destination? I can only see the option in my implicit rule where I can choose Load Balancing Algorithm. In all other rules above I dont get the option?

 

Thanks

gfleming

Well which rule is the SAP traffic hitting? Is it the implicit rule or some other rule? Just change your implicit rule to soure-dest load balancing for now and work from there..

Cheers,
Graham
Labels
Top Kudoed Authors