Hello,
I have configured Wan fail over for win1 and wan 2. I have IPSec configs for both wans. Normal operation on wan1 site-to-site IPSec tunnels are working fine. When wan 1 goes down wan 2 kicks in and IPSec site-2-site tunnels
kick in and work fine. BUT when wan 1 comes back up the site-2-site tunnels do not come back up and or they show "up" in IPSec monitoring but they do not pass traffic.
How exactly did you configure two parallel static routes (config router static) and link-monitor (config sys link-monitor)? Did you make the static route via wan1-ipsec preferred. And the link-monitor is removing the preferred static route? When you check the routing-table (get router info routing-t all) when wan1 has come back up you could find why it doesn't fail-back.
If it helps: I here do this with routing priorities. I.e. I have a static route for every ipsec point to point tunnel to every subnet I need. Every Site has two redundant IPsec tunnels on two diffeent wans.
So I just set the route for the first tunnel to have a lower prio than the route for the 2nd.
FGT then primarily uses the first tunnel and if that goes down it switches to the 2nd. If the first ne comes back up again it switches back due to priority.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.