Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jokes54321
New Contributor III

SDWan, making sense of Update Static Route slider

My team has been deploying a lot of SDWan lately with DIA and Broadband circuits. We have a couple of sites that have frequently been reporting session disconnects from cloud hosted applications and SIP phones that suddenly lose audio.

 

I asked the sites to start reporting the exact times so I could correlate their issues to events in the logs. So far, each reported event seems to correlate to SDWan changes. Digging in deeper, neither of the circuits seem to be dropping, just falling outside the defined SLA values.

 

Each time it was reported, I checked the active sessions on the firewall for the impacted phones and saw the destination interface being used didn't match the interface SDWan was preferring at the time.  This leads me to believe the SDWan decisions are impacting existing connections.  

 

If I have the "Update Static Route" slider enabled, and a circuit doesn't meet the defined SLA requirement, will it break existing connections by removing the route, but keep the sessions active in state?

 

 

When would a person want to enable this slider and when would they want to keep is disabled?

 

Denny   

2 REPLIES 2
akristof
Staff
Staff

Hello,

 

Option update-static-route will remove route from routing-table only if the health-check for that interface is dead. If it is out-of-sla, it will be still in the routing-table.

If you have SLA targets enabled for health-check, if the metric will be not within, then the interface might not be used in sdwan rule and other interface will be preferred.

Adrian
gfleming
Staff
Staff

How are your SIP phones connecting across your WAN? Do you have IPSec tunnel? Or is it going to Internet somewhere? If it's using internet you are likely doing NAT. When SD-WAN SLA causes a new interface to be used you will be establishing a new session with new SNAT and that will break SIP communications as it has to reconnect. 

 

If you have IPSec tunnel overlay you can switch between WAN links seamlessly...

Cheers,
Graham
Labels
Top Kudoed Authors