I have an SDWAN with 2 ISP each assigned it's own real IP.
I am working all the time on ISP1 with failover and switch to ISP2 in case 1 goes down.
Basically, I need a new rule just to redirect or allow all traffic from 1 Lan IP to ISP2 please, while all the rest of the Lan keep working on ISP1.
And I will disable this new rule whenever I don't need it.
Things I tried , create a new policy but all I can assign is the sdwan, I cannot choose between ISP.
If you have SDWAN already implemented, you will simply need to create a new SDWAN rule and specify the LAN IP as source. You will then manually select the outgoing interface there.
Note that SDWAN rules are assessed from to to bottom, so you will likely need to place this SDWAN rule at the top.
More details can be found at https://docs.fortinet.com/document/fortigate/7.2.8/administration-guide/413288/sd-wan-rules-overview .
I can't modify the SDWAN , not sure why.
creating a new sdwan rule and adding isp2 did not work , i guess because ISP2 interface is already assigned.
Also trying to remove isp2 from the original sdwan did not work.
You don't need to create a new SD-WAN, just keep both ISPs in the same SD-WAN interface.
In your SD-WAN rules, you need to have the top most rule like this:
And in your firewall policy you use your SD-WAN interface as outgoing interface:
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1737 | |
1107 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.