Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HS08
Contributor

Sdwan Asymetric

I have 2 site to site from site-A to site-B and sdwan only enabled in site-A

In the site-B I configure static route to site-A via 2 link with same cost.

The issue is when site-A select link-B for example then site B reply using link-A.

How we can prevent this kind of asymetric?

6 REPLIES 6
AEK
SuperUser
SuperUser

No SD-WAN in site B.

This one should be fixed with policy route.

AEK
AEK
Toshi_Esumi
SuperUser
SuperUser

If 1) site B is a FGT, 2) those two interfaces at site-B back to site-A are NOT in an SD-WAN group, and 3) those are really "reply/returning" packets, it should never happen. Because the site-B FGT has a session established to return the session's returning packet to the interface the initiation packet came in. 
so, those are either a) not reply packets but initiated by site-B, or 2) the site-B doesn't have a proper route to the interface the initiation packet came in.

Toshi 

HS08

Both site using Fortigate, when connection from site-A to site-B via link-A have bad performance, i can see in fortigate session site-A the traffic flowing to the link-B.

But when i check session in site-B, the traffic is using link-A.

Toshi_Esumi

Because the link was changed while the session is still alive. Site-B needs to have the same members in an SD-WAN zone, then the same session on the B-side should still work. You probably want to set the same rules and SLA settings on the B-side so that it fails over to the other side for B-initiated session.

Toshi

HS08

so we can't enable the sdwan only in one side to steer the traffic?

Toshi_Esumi

If multiple paths to the same FGT are in a SD-WAN zone, it seems. You should test it yourself to confirm. It's just my theory based on what you're observing.

Toshi

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors