Hi,
I have a FGT 100D with a dual WAN configuration.
First WAN is getting IP etc. via DHCP from Provider.
Second WAN has Manual IP, GW etc Settings.
Both WAN Links have the same distance but different priority for Failover.
Routing is set as:
config router static edit 1 set priority 1 set device "wan1" set dynamic-gateway enable next edit 2 set gateway 217.110.xx.xx set priority 2 set device "wan2" next end
There is a policy route to force port 25 traffic over wan2.
Every hour or so, the route for the second wan is missing in Routing Monitor, means it isn't active any longer. I have to restart the FGT to resolve the issue.
Has anyone some advice for me where to look for the error? I see nothing in the Event logs.
Attached are Pictures of Routing Monitor in OK state and when error is present.
Thanks in advance!
Tim
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Qs:
Are you using dead-gateway detect?
Are you 100% sure the interface is not going down?
PCNSE
NSE
StrongSwan
emnoc wrote:Qs:
Are you using dead-gateway detect?
Are you 100% sure the interface is not going down?
Hi,
currently,I do not use dead Gateway detect. For clarification: This would be to monitor if link 2 goes down, right?
I am quite sure that WAN2 is not down. If i sniffer WAN2 during the precense of the error, I see incoming SMTP request, but never an ack (because the ack of the mail Server is then not routed through wan2. If it was down, sniffer would not see incoming request from Internet Hosts.
If you have not done so already, I suggest setting up Dead Gateway Detection on both WAN ports. Also I would check the status on WAN2 (e.g. perform a diag hardware deviceinfo nic wan2) for a possible duplex/speed issue.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Dave Hall wrote:If you have not done so already, I suggest setting up Dead Gateway Detection on both WAN ports. Also I would check the status on WAN2 (e.g. perform a diag hardware deviceinfo nic wan2) for a possible duplex/speed issue.
What I found out:
When the error is present and I set the WAN2 Priority lower than wan1 priority, suddenly WAn2 Shows up in Routing Monitor - but now of course as the Default route which I don't want.
Could it be that the WAN2 route gets stale or something like that - Only SMTP goes over it (because of the corresponding policy route) and the can be 10 - 15 Minutes when nothing really happens SMTP-wise
Tim
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.