Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ozzy1903
New Contributor

Wan link sharing in redundant SDWAN design

Hi All

 I am at initial phase of a SDWAN deployment. I will have dual FWs in branches. I can connect my internet connection as full mesh to my fortigates. However my mpls provider is proving only one physical connection with /30 subnet. So i can connect it only to one device. Can i do some magic to make fortigates to share my mpls link for sdwan?

4 REPLIES 4
lobstercreed
Valued Contributor

The only way I know of is to add a switch in between.  It does add a single point of failure but you're already looking at that with the provider's setup.  This is what we do, as our ISP's only give us one port each.

mahesh_secure

Hi

 

as mentioned by @lobstercreed 

 

you need fortiswitch or any other l2 switch that support stacking.

 

create a vlan in switch and add 3 port to that vlan in access mode. 

 

example:

 

port 1 

port2

port3

 

in vlan 2 with access mode. connect MPLS to port 1 and from port 2 to 1st firewall and port3 to 2nd firewall

 

 

Regards

Mahesh

ozzy1903

But ISP is giving me /30. Will firewalls share the only one available IP?

lobstercreed

Yes, if they are in HA, which was my assumption since you said dual FWs.  Are they not HA?  If not, why not?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors