I have created 1 Hub with 2 branch office ( No forti manager ) , HUB having 2 ISP with static IP , branch having 2 ISP with dialup. created tunnels and created aggrigate tunnel. but fail over not hapening. some time 1 tunnel will work. routing also not working. can anybody help for the best practice / document for the config
Hi!
Make sure to use IP SLA to verify the working of the remote site.
If you're using BGP make sure multipath is enabled
I would recommend changing the aggregate IPsec to SD-WAN overlay make use of "Maximize bandwith"
Can you please share the link/doc for the configuration
For SD-WAN?
Please follow this guide:
Deployment procedures -> WAN edge -> Overlay -> Defining SD-WAN zones for the overlay
Deployment procedures -> WAN edge -> Overlay -> Defining SD-WAN members
Deployment procedures -> WAN edge -> WAN edge intelligence -> Defining performance SLA
Deployment procedures -> WAN edge -> WAN edge intelligence -> Creating SD-WAN rules.
Goodluck!
| User | Count |
|---|---|
| 2910 | |
| 1451 | |
| 850 | |
| 825 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.