I have configured a default route via a SDWAN zone for Internet breakout traffic, this consists of two internet connections. The default route via this SDWAN zone is not being populated in the routing table, both interfaces are up and working.
For testing I set a default route out WAN1 and then WAN2 separately, they were both able to reach the internet and the default route was stored in the routing table.
Any possible ideas why the route is not being installed and working with the SDWAN zone?
You should see one default route with the two SD-WAN members, something like this:
FW # get router info routing-table details
S* 0.0.0.0/0 [10/0] via 192.168.1.1, wan1
[10/0] via 192.168.2.1, wan2
I have two ISPs, both DHCP and I spent 6 hours trying to wire up SD-WAN on a freshly installed Fortigate 7.6.3. The symptom was the same: default route did not appear despite of being correctly set. As a consequence, no any communication outside worked while I've been seeing that metrics in SLA to outside sites (e.g. ping to 8.8.8.8) working normally. I also, like you, tried to use WAN interfaces directly, without SD-WAN and they both worked normally.
Finally I specified an ISP gateway manually in SD-WAN member settings, just retyped what I received from DHCP and it's started to work. Then I reverted setting back to "Dynamic" and it still works, even after reboot.
I'm not sure what was the root cause but this article gave me a clue what I can try when I nearly gave up:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-SD-WAN-is-not-in-Active-Routing-Table/ta-p...
The KB you referred to has a static IP on both interfaces. That's why the gateway has to be configured somewhere. In case of DHCP, it shouldn't be needed. I never configured with my SD-WAN setup since both circuits are either PPPoE or DHCP. Something else must have caused when it was not working.
Toshi
Technically, 0.0.0.0/0 is a static gateway. I'm pretty sure this is a firmware bug, probably related to Bug Id 896277, caused by selecting "all" for destination through the GUI. Despite of default object of "all" = 0.0.0.0/0, static gateway of 0.0.0.0/0 is not saved in this case to a WAN member. Workaround is to temporary save real static IP, or specify 0.0.0.0/0 through CLI (not sure, not tested but most likely will work).
User | Count |
---|---|
2570 | |
1362 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.