Hello everyone,
We are trying to setup SD-WAN on Fortigate 30E device with FortiOs 6.2.3 and 2 PPPOE WAN connections.
One ISP is one WAN port and other ISP is on Port 4 that is setup as WAN interface. Both ISP connections are tested individually and the connection is working as expected.
SD-WAN interface is created with 2 members with same cost (0).
Static route is created to subnet 0.0.0.0/0.0.0.0, interface SD-WAN, Administrative distance 1.
Central SNAT policy is created with Incoming interface: lan, Outgoing interface: both WAN ports, Source address: local subnet, Destination address: all, NAT turned on, IP Pool Configuration: Use Outgoing Interface Address, Protocol: any, Explicit port mapping turned off.
Security policy from lan to SD-WAN is created with Incoming interface: lan, Outgoing interface: SD-WAN, Source address: local subnet, Destination address: all, Schedule: always, Service: ALL, Action: Accept, Inspection mode: Flow-based.
When we set NGFW mode to Profile-based with Central SNAT turned On in System\Settings, SD-WAN works perfectly. Even with the SD-WAN rules, everything works.
When we set NGFW mode to Profile-based an create same security policy, there is no Internet access at all.
Are we missing something or SD-WAN does not work with Policy-based NGFW?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1516 | |
1013 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.