I have two network segments: 10.100.x.x and 10.200.x.x networks. I've successfully established a VPN tunnel between these two different subnets using Fortinet FortiGate-60F(SD-WAN). I have configured a virtual server with the following setup:
Issue: When I shut down the server at 10.200.0.102, the traffic is not being forwarded to 10.100.0.102 as expected. The load balancing/failover mechanism doesn't seem to be working across the VPN tunnel. Network Topology:
Questions:
Any guidance or suggestions would be greatly appreciated. FortiGate Model: FortiGate-60F FortiOS Version: V7.2.6
The remote firewall must allow the local firewall to reach the back-end server (10.100.0.102). You need to add a rule for that on the remote firewall.
Then try connect to the second back-end server (10.100.0.102) from the local firewall to confirm it is reachable on the related service port.
exec telnet 10.100.0.102 443
Hope it helps.
hi, on the virtual server have you configured the real servers as active/standby ?
if so, when you shut down the first server/active , can you confirm that the FGT sees it as down from the Load Balance dashboard ?
if not, try setting inside the virtual server a health check for them.
as for the fw rules, since it uses backend servers towards different subnets and potentially different interfaces, do you have fw rules in place towards them where the destination is the VIP ?
User | Count |
---|---|
2554 | |
1356 | |
795 | |
647 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.