If I have a Fortigate 60F with 2 ISPs setup as an SD WAN interface, how do I setup inbound NAT so that it works with the failover ISP? For instance, I have several VIPs and inbound NATs currently tied to the primary ISP public IP address. Now I have a 2nd ISP, what happens to the ability to connect into the network if the primary ISP goes down?
Create two VIPs, one for each wan interface. Note you won't be using SD-WAN to determine how outside clients connect to you. You'll need some form of mechanism so clients know not to connect to your dead ISP. DNS failover is one method of doing this where you use external health checks to dynamically update your DNS pointers...
Hello
You can set the VIP only to one WAN address. in DNS you can also set only one address.
As Graham already wrote make a simple 2 VIP with the 2WAN address.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1751 | |
1114 | |
766 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.