Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jwegner
New Contributor

SD-WAN and Zscaler Internet Access (ZIA)

Does anyone know if the Maximize Bandwidth SLA option is supported in the SD-WAN rules when connecting across tunnels to Zscaler Internet Access (ZIA) Cloud on-ramp? The documentation I've found recommends using Link-Cost for failover between a primary vpn tunnel across ISP1 and a secondary vpn across ISP2. Each to a separate Zscaler Public Edge. I'm trying to build 4 tunnels, 2 from each ISP to each Public Edge, and load balance across all 4. Has anyone attempted this? 

5 REPLIES 5
amrit
Staff & Editor
Staff & Editor

The maximum bandwidth option in sdwan load balances the traffic among all the interfaces that satisfy SLAs. This can also be configured without SLA. So basically traffic will be sent out in round-robin manner on all the

participating interfaces. So if this supported by Z-scaler you can configure this on fortigate without any problem.

For further clarification you can read this document : https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/708464

Amritpal Singh
jwegner
New Contributor

I can't think of any reason why it wouldn't work. But I'm unable to find documentation specific to load balancing to Zscaler Public Service Edge. I would think that each Public Service Edge needs to operate independently from every other Public Service Edge in order to keep traffic separated.

istvanmarlok
New Contributor III

Hi!

 

Did you implement this with load balancing on ZIA? I’d like to do the same, but the guide explicitly says it should be configured as active-passive.

 

Thank you!

jwegner
New Contributor

ZIA always makes tunnels in pairs, a primary and secondary ZIA endpoint. Hence the guide stating the need for active-passive tunnels. However I had a wan1 and a wan2 link to play with, allowing me to make 4 tunnels, 2 primary's and 2 secondary's. All 4 GRE tunnels went into a sdwan zone. And at the end of the day all the customer needed was manual failover. There shouldn't be anything stopping you from using lowest cost sla as long as the 2 primary GREs are preferred. You might even be able to load balance all 4 in a single rule if you raise the 2 secondary GREs priority value. Or just use 2 rules, primaries and secondaries.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors