We have a Fortigate 100F with WAN1 only. We are getting a secondary connection setup and want to setup to failover in case WAN1 goes down. My question is, is there a way to setup WAN failover without creating any downtime? If so, what is the best way to do so? If we setup SDWAN and add WAN1 and WAN2 as members, will it create downtime until we create the correct policies for SDWAN? Any suggestions/recommendations are appreciated!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @Sterling-BF ,
Have a look here it may help with your configuration :
https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/889544/sd-wan-quick-start
Hi@Sterling-BF,
To configure SD-WAN the Port should not be part of any configuration on firewall, you would need to remove all the references of the port.
You can also achieve the redundancy without configuring the SD-WAN, please refer to below article:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Redundant-Internet-connection-without-load...
https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/360563/dual-internet-connect...
Regards,
Abhimanyu
@Sterling-BF
You should consider:
1. First configure SDWAN zone and add backup line as a member. (lets say zone1)
2. Configure firewall policies and all other settings the same way you have for wan1
3. Configure static routing the same way you have for wan1 but with lower priority
4. After everything is configured the same (duplicate) change routing priority of sdwan and route all traffic through sdwan zone1.
5 You will not notice traffic rerouted.
6. Start cleaning everything where you have configured wan1
7. Add wan1 in sdwan zone (note that if that is not removed from all settings, you can not add it)
8. Create sdwan rule to use wan1 as primary interface.
Hope this helps.
Do not forget to do more research on each step.
.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1721 | |
1098 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.