I have 2 site to site from site-A to site-B and sdwan only enabled in site-A
In the site-B I configure static route to site-A via 2 link with same cost.
The issue is when site-A select link-B for example then site B reply using link-A.
How we can prevent this kind of asymetric?
No SD-WAN in site B.
This one should be fixed with policy route.
If 1) site B is a FGT, 2) those two interfaces at site-B back to site-A are NOT in an SD-WAN group, and 3) those are really "reply/returning" packets, it should never happen. Because the site-B FGT has a session established to return the session's returning packet to the interface the initiation packet came in.
so, those are either a) not reply packets but initiated by site-B, or 2) the site-B doesn't have a proper route to the interface the initiation packet came in.
Toshi
Both site using Fortigate, when connection from site-A to site-B via link-A have bad performance, i can see in fortigate session site-A the traffic flowing to the link-B.
But when i check session in site-B, the traffic is using link-A.
Created on ‎09-21-2025 05:44 PM Edited on ‎09-21-2025 05:44 PM
Because the link was changed while the session is still alive. Site-B needs to have the same members in an SD-WAN zone, then the same session on the B-side should still work. You probably want to set the same rules and SLA settings on the B-side so that it fails over to the other side for B-initiated session.
Toshi
so we can't enable the sdwan only in one side to steer the traffic?
If multiple paths to the same FGT are in a SD-WAN zone, it seems. You should test it yourself to confirm. It's just my theory based on what you're observing.
Toshi
User | Count |
---|---|
2638 | |
1400 | |
810 | |
684 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.