Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kxs
New Contributor

dual WAN ipsec

Hello, I have an FG60F in the HQ with dual WAN. WAN1 distance 5 and WAN2 distance 10. Is it possible to set up an IPsec VPN over WAN2 to a branch office without SDWAN?

4 REPLIES 4
sw2090
SuperUser
SuperUser

yes it is. In IPSec you can either use SDWAN-VPN if you want it to be redundant or you can still do without SDWAN and use the wan on its own for a tunnel (and do redundancy by routing priority).

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
kxs
New Contributor

I tried that. I can only set up a tunnel if WAN2 has a shorter distance than wan1. This means that all internet traffic from HQ goes over WAN2. I have already experimented with static routes, administrative distance and priority. Doesn't work. Are there any instructions on how to do this?

sw2090
SuperUser
SuperUser

hm strange.

 

Internet traffic will use the route that SDWAN chooses accoarding to the matching sdwan rule.

However you tie an IPSec to an interface so it will use that interface to talk to the remote gw. It definitly does do that here.

Traffic will then use the IPSec (once established) if it matches any static route over the IPSec.

I always had to IPSec S2S tunnels per site over two different WANs and the routing prio in the static routes for the site subnets gave which IPSec  had to be used. So it primarily used the matching route with lowest prio and if that one was down it used the other.

Meanwhile I'm using SDWAN-VPN for this. 

-- 

"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

-- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
hbac
Staff
Staff

Hi @kxs,

 

Both WANs should have the same distances. 

 

Regards, 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors