I have a FortiGate 70f firewall with two ISP connections configured on WAN1 and WAN2. I have configured static routes for both the WAN interface, also created firewall policies for both the interface. But when my WAN1 is goes down, the failover to WAN2 is not working, I have to disable the down WAN interface static route then it divert traffic to WAN2. I don't have anything running on this firewall as this is new device and want to test it first and then put it on production environment. Here the my setup is little different, I kept normal unmanaged 8 port switch between ISP and Firewall, means ISP first comes in my 8port switch then from switch to Firewall. If I connect ISP directly back to the firewall it works perfectly, it only give me an issue when I have 8port switch between ISP and Firewall. I need expert advice on this issue. Thanks in advance.
The (default?) static route stays up unless the interface/wan1 goes down. If you have a switch, even when ISP's L1/L2 goes done, the wan1 port never goes down. You need to set up a link-monitor over wan1 interface then it would remove the static route when the link-monitor fails.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Link-Monitor-Explained/ta-p/197504
Toshi
User | Count |
---|---|
2606 | |
1389 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.