Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Paresh
New Contributor

WAN Failover - Static to PPPOE

Hi ALL

 

Please may someone give me advise. I currently have a fortigate 60D. WAN1 has a static IP with IPsec VPN's. I have another ISP which is PPPOE (I want to configure on WAN2). How would configure a failover. When WAN1 is totally down WAN2 takes over?

 

I have seen many posts but their either using both static IP's which makes it easier.

 

Thanks in advance.

3 REPLIES 3
ronalds_567
New Contributor

Hello

 

You may use Wan Link Load Balancing for failover or for share load. You should disable on the pppoe interface the option to obtain the default gateway( you must learn first what address use the pppoe as gateway ) and then assing it manually into the WLLB config.

 

Otherwise, if you have problems with the PPPoE route, you can create an exclusive VDOM for the PPPoE and use Virtual link with static address for the WLLB configuration on the vdom root and leave the PPPoE-VDOM with the route learned through PPPoE.

 

http://cookbook.fortinet....ternet-connections-54/

ronalds567
ronalds567
Paresh

Hi Rruizdiaz

 

Thank you for your reply. I did see this link you referred to but it was not clear on the PPPoE part. I assume that the PPPoE configuration will retain the same default gateway?

 

Why do you assume that I might have an issue with "PPPoE route"? What about the "Distance" on the PPPoE & "Retreive Default Gateway from server"?

 

How would this configuration affect my IPsec VPN that is terminating on WAN1?

 

Thanks again.

ronalds_567

Hi Paresh

For implement WLLB you need to set staticly the gateway address under Network>WAN LLB. Is yours PPPoE address static or dynamic? If it is static, you must disable the "Retreive Default Gateway from server" option and you could treat it like a common WAN connection with manually IP assigment. The advantage using WLLB is that you will create only a default route 0.0.0.0/0 throught the virtual-wan-link without especifying any gateway address or physical interface because you define it under WAN LLB members setting. In this way, both public IP will be reachable and you can have any active IPsec VPNs over both ISP at the same time. If you check the active routes, you will see 2 default routes throught 2 different interfaces( This is not posible configuring staticly or dynamicly 2 default routes using metrics or distance)

If your PPPoE address is dynamic,maybe there is a problem for implementing WLLB if the gateway address change as the IP address change. In that case you can create a new VDOM for the PPPoE using the "Retreive Default Gateway from server" option activated, and in the other hand, in the VDOM root you will use the virtual-link(the inter-VDOM conection) as member of the WAN LLB with private and fixes address. Of course, there are more routing and policies configurations.

I hope it helps.

Regards,

Ronald

 

 

ronalds567
ronalds567
Labels
Top Kudoed Authors