Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sw2090
SuperUser
SuperUser

WLLB contra Policies on WAN Interfaces - any advices?

Heyho,

 

I have the following (not really uncommon *g*) setup:

 

FortiGate is connected to a router via one WAN Interface and to annother router via annother WAN.

Both WANs are in WLLB and doing some Loadbalancing.

 

Now let's say WAN1 has a static IP setup to reach that router and the WLLB knows the Gateway. Default Route is on WLLB.

Internet + WLLB works fine so far.

 

However it is impossible to create a policy granting access from somewhere inside to the Net the WAN1 is in because you cannot select WAN1 as destination nor source interface anymore.

I come in via remote by IPSec VPN and want to be able to access that router from here. That would require a policy at remote sinde but as I said I cannot create it.

 

Can anyone help me to understand why fortinet made this limitation? I cannot see any sense in not allowing this.

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
5 REPLIES 5
Anurag_Goyal
New Contributor

you can do all the things as you want but you need to share the model of FGT with version.

Anurag Goyal

Anurag Goyal
sw2090

This ist not a model specific issue. I encountered this on a 100D,100E,60E,90D,...

I'd consider it to be more a  "Feature" of FortiOS v5.4.x or greater.

It generally happens to you on v5.4.x (I don't have any v5.6.x so can't say if it is there too) and it does not matter which FGT model you have alas it is able to run 5.4.x of course ;)

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Anurag_Goyal

"However it is impossible to create a policy granting access from somewhere inside to the Net the WAN1 is in because you cannot select WAN1 as destination nor source interface anymore."

1. Define the IP of your router in "Addresses" with particular interface.

2. Create the policy "Source-your inside interface with your desired user's ip/IPSec user or all", Destination-WLLB with your router's IP as you created.

that's it.

Anurag Goyal

Anurag Goyal
sw2090

Aah ok :) You never stop learning xD

Yes it does work that way! Many thx to you!

 

cheerioh

Sebastian

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Anurag_Goyal

your welcome

Anurag Goyal

Anurag Goyal
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors