Hi,
I request your help for a routing configuration in my fortigate,
I have received a box from OVH (technicolor), in my firewall I have 2 box connected (the OVH box on wan1 and another box on wan2). the 2 box have the same settings and I put the same policy rules on the 2 interfaces. My problem is when I try to use my Voip phones they only take the way of the wan2, when I desactivate the "voip rule" on wan2, the rule on wan1 does not work.
To be clear about this, I want to use the wan1 for Voip only and the wan2 for web traffic and datas.. I put a policy route to wan1 but it does not seem to work. I have my system/config HA configured in standalone mode,
my heartbeat interface:
dmz enable 50 lan 0 wan1 enable 50 wan2 0 On My static route: the wan2 priority and distance are set on 10 the wan1 priority and distance are set on 5 I tried with my box set on bridge mode also in routing mode, but the result is the same. Any idea about this problem ? I probably made a mistake in my configuration... Sorry for my poor english, thanks in advance for your assistance.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I never heard of that bob, but what he should do is pull the route table. I prefer the cli since I'm a cli guy;
e.g
get router info kernel
or
get router info routing-table database
Both of these gives a clear picture of the routes.What I like about the latter it will show you all routes including the prority;
S *> 0.0.0.0/0 [10/0] via x.x.x.x, wan1, [100/0]
S *> 0.0.0.0/0 [10/0] via y.y.y.y.y, wan2, [200/0] S 0.0.0.0/0 [254/0] is a summary, Null
So it's easy to understand the RIB.
For the >OP< he really needs to run the diagnostic command and then look at the route table for unicast or PBR and adjust as required and re-run the diagnostic debug flow.
Ken
PCNSE
NSE
StrongSwan
rwpatterson wrote:
If you change it to an odd number and the gateway changes, then it is the FGT doing 'gateway load balancing'. Even IP addresses use the WAN2 and odd IP addresses use WAN1. Test and let us know how it goes.
emnoc wrote:'gateway load balancing' That's not an official term, it's just what I call it based on the behaviors I have seen on several of the smaller models. (100A, 80xx, 60x, etc.)I never heard of that bob, but what he should do is pull the route table. I prefer the cli since I'm a cli guy;
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.