Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Juraj
New Contributor

SMTP to the mail server from 2 WAN

Hi everyone, I have a dual WAN scenario - on WAN1 VIP on port 25 to the server on internal. I' d like to setup a disaster scenario in case that WAN1 goes down so we can continue business through WAN2. The problem is that I obviously can' t setup another VIP on port 25. How to go around that? How do you solve those problems? I had a lok in kb http://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD31240&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=21224799&stateId=0%200%2021226533 but that' s a bit different issue as it uses WAN2 solely for SMTP. FW is v4.0,build0291,100824 (MR2 Patch 2) Thank you.
Quality of your life depends on the quality of the questions you ask.
Quality of your life depends on the quality of the questions you ask.
12 REPLIES 12
Juraj
New Contributor

Thanks for the explanation. I still don' t entirely understand the concept but have tried it and it works (which surprises me a bit). I setup the other VIP as coming from my WAN2 on port 25 to the exchange server and it works! I was under the impression that it won' t so thank you for your input everyone, mainly ede_pfau.
Quality of your life depends on the quality of the questions you ask.
Quality of your life depends on the quality of the questions you ask.
siomyn
New Contributor III

Hi Ede,

How about the outbound traffic? if we have round robin LLB for outbound traffic, mail server will sent the outbound mail to wan1 or wan 2 randomly. 

Is the recipient will detect our emails as spam? because inbound will use wan1 (primary MX) and the outbound email will use either wan1 and wan2 (randomly).

 

Thanks, 

OMYN

Technical Consultant | Indonesia CCNP Security, Fortinet NSE 

OMYN Technical Consultant | Indonesia CCNP Security, Fortinet NSE
ede_pfau

I don't think it will switch with every connection but I'm open if you can correct me.

 

AFAIK the LLB is done based on a hash of the source address. If that is indeed the case only one WAN port will be used for traffic from a specific host, all the time. If both source and destination address were hashed it would use  both ports, albeit with no foreseeable weights.

Needs testing if someone can sacrifice the time...

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors