Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

VIPs and using both WAN interfaces

Here' s my setup. We have DSL on one WAN interface and a T1 on the other, with VIPs setup on each interface for each service we offer. So we have a VIP on WAN1 for port 25 and a VIP on WAN2 for port 25, both pointing to the same internal IP. I have a static route for each WAN connection, so that all traffic is prioritized to WAN1 with WAN2 as a backup. My issue is, with this config, I seem to only be able to connect to services made available on whichever interface has the preferred static route. So, if WAN1 has a cost of 1 and WAN2 has a cost of 10, I can get to services on WAN1 externally. But if I swap the costs, I can only get to services on WAN2. I have no policy routes setup. Any idea what' s going on?
4 REPLIES 4
rwpatterson
Valued Contributor III

Traffic passing from the VIP on the higher cost port is trying to return on the default lower cost one, and the routing is getting buggered (as the Brits would say). I know the cause, the repair is another matter. I' ll pass this one on, but at least you know why.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com

I figured traffic was coming in on one interface and going out the other, but couldn' t see how to fix that without policy routes. A call to support yeilded the answer. I needed the cost for both routes to be equal (10) and then needed to configure route priority through the CLI: As we discussed on the phone in order to be able to use VIPs on wan1 and wan2 interfaces simultaneously you' ll need to reconfigure your Fortigate from failover mode to load sharing mode. Configuration steps: 1) access your Fortigate CLI and type: config router static edit 1 set priority 10 next edit 2 set priority 20 end 2) access the GUI and change wan1' s default route distance to 10 The instructions above will set up your Fortigate to: - accept incoming connections (VIPs) on both external interfaces (wan1 and wan2) - use wan2 for outgoing traffic and wan1 for failover
doshbass
New Contributor III

Bugger, bugger, bugger and by jove what what!! Just to prove Bob' s point. To fix this, try inbound NAT (check the nat checkbox). The problem with this is that you cannot see from which IP address the connection is coming on your mail server, and this could kill some antispam functions.
Still learning to type " the"
Still learning to type " the"
gbaharoff
New Contributor

I' m glad you asked this question because I' m about to deploy a solution that will have two Internet circuits in use. I don' t understand the configuration steps you described though. 1) This commands appear to set the priority to different value??? 2) Changes the one at 20 back to 10???? Then your description at the end says that it will accept traffic from both WAN ports but only send it out one??? I thought your objective was to change from failover mode to sharing mode, but your last line says " use wan2 for outgoing traffic and wan1 for failover." I thought that wasn' t want you wanted to accomplish. Bottom line is will what you' re listing as steps allow both circuits to be used simultaneously? Isn' t the problem with all traffic going out one wan port but coming in both is that the response back from the Fortigate doesn' t reach the initial recipient?
Greg Baharoff Fortinet Certified System Engineer MTBW Services, Inc. 327 E Ridgeville Blvd 154 Mount Airy MD 21771 301-829-5925
Greg Baharoff Fortinet Certified System Engineer MTBW Services, Inc. 327 E Ridgeville Blvd 154 Mount Airy MD 21771 301-829-5925
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors