Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
erichard
New Contributor

SD-WAN keep the same ip if wan1 or wan2 down

Hello,

We have actually a wan1 connection with the interphace ip 80.xx.xx.xx (it's a private ip of our FAI named "SFR"). We have 5 VPN connection between our fortinet and other pfsense. All pfsense use the remote ip 80.xx.xx.xx of our fortinet. And also we have domain names that point to ports on our fortiner. For exemple test.mydomain.com:8080 point to 80.xx.xx.xx and a rules nat the port 8080 in a server behind the fortinet. Everything works fine.

But now we will install a backup internet connection on wan2 with a other FAI named "ORANGE" with the private ip 193.xx.xx.xx. For our users continue to use internet if wan1 is offline, i have to create a new sd-wan contains wan1 and wan2. This should work for the user continue to have internet transparently by wan2.

But for the VPN connection and the redirect port 8080 will it work ? Actually without sd-wan, the VPN is broken if wan1 80.xx.xx.xx is offline (it's normal). And we needs to have a backup link for if wan1 is offline, vpn can continue to work automatically with wan2. The sd-wan could keep the ip 80.xx.xx.xx.xx available if wan1 (80.xx.xx.xx) is offline and wan2 (193.xx.xx.xx) is online ?

I search how to keep the private ip online if wan1 or wan2 is offline.

Thank you for your help.

3 REPLIES 3
amrit
Staff
Staff

For the ipsec vpn connections, you need to create a backup tunnel on the wan2. For SSL VPN connections  your users need to use the IP address of the wan2 when wan1 is offline

Amritpal Singh
kajlasunil

Hi @erichard 

For the test.mydomain.com:8080 NAT configuration, you may need to make sure the DNS record points to the backup internet when WAN1 is down. If you are using fortiDDNS service then the fortigate will automatically update the DNS record with active internet connection.If the DNS record is hosted on third party then you may need to check with them if there is any way to dynamically update the DNS record.

ks
Shashwati
Staff
Staff
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors