Hi ALL
Please may someone give me advise. I currently have a fortigate 60D. WAN1 has a static IP with IPsec VPN's. I have another ISP which is PPPOE (I want to configure on WAN2). How would configure a failover. When WAN1 is totally down WAN2 takes over?
I have seen many posts but their either using both static IP's which makes it easier.
Thanks in advance.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello
You may use Wan Link Load Balancing for failover or for share load. You should disable on the pppoe interface the option to obtain the default gateway( you must learn first what address use the pppoe as gateway ) and then assing it manually into the WLLB config.
Otherwise, if you have problems with the PPPoE route, you can create an exclusive VDOM for the PPPoE and use Virtual link with static address for the WLLB configuration on the vdom root and leave the PPPoE-VDOM with the route learned through PPPoE.
http://cookbook.fortinet....ternet-connections-54/
Hi Rruizdiaz
Thank you for your reply. I did see this link you referred to but it was not clear on the PPPoE part. I assume that the PPPoE configuration will retain the same default gateway?
Why do you assume that I might have an issue with "PPPoE route"? What about the "Distance" on the PPPoE & "Retreive Default Gateway from server"?
How would this configuration affect my IPsec VPN that is terminating on WAN1?
Thanks again.
Hi Paresh
For implement WLLB you need to set staticly the gateway address under Network>WAN LLB. Is yours PPPoE address static or dynamic? If it is static, you must disable the "Retreive Default Gateway from server" option and you could treat it like a common WAN connection with manually IP assigment. The advantage using WLLB is that you will create only a default route 0.0.0.0/0 throught the virtual-wan-link without especifying any gateway address or physical interface because you define it under WAN LLB members setting. In this way, both public IP will be reachable and you can have any active IPsec VPNs over both ISP at the same time. If you check the active routes, you will see 2 default routes throught 2 different interfaces( This is not posible configuring staticly or dynamicly 2 default routes using metrics or distance)
If your PPPoE address is dynamic,maybe there is a problem for implementing WLLB if the gateway address change as the IP address change. In that case you can create a new VDOM for the PPPoE using the "Retreive Default Gateway from server" option activated, and in the other hand, in the VDOM root you will use the virtual-link(the inter-VDOM conection) as member of the WAN LLB with private and fixes address. Of course, there are more routing and policies configurations.
I hope it helps.
Regards,
Ronald
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.