Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
virenlad
New Contributor

fortigate config

Dear all, we have fortigate 80c with mr2patch12 we have two wan port attached to different ISP. we have one internal network 192.168.1.0/255.255.255.0 i want internet surfing for some website to go through wan1. other websites to go through wan2. we dont want load balancing config & also dont want redudndant backup config.. can anybody suggest us how to config fortigate to use both wan port at same time for internet surfing
5 REPLIES 5
emnoc
Esteemed Contributor III

PBR policy-base-routing by destination/source protocol.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau
SuperUser
SuperUser

...PBR by destination address... See the FortiOS Handbook for v4.00 MR2 at http://docs.fortinet.com

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
emnoc
Esteemed Contributor III

He can actual use the source(s) option, if he has a need for only certain sources to go to those destinations. FWIW: Policy routing exceeds static or dynamic routing.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
ede_pfau
SuperUser
SuperUser

Glad you made me re-read my post. Actually, he doesn' t need any PBR at all. Routing by destination address (" surfing to a certain website..." as the OP clearly expressed) is done by regular routing! Which IMHO is much more transparent and comfortable in general. So, virenlad, if you want to surf to, say, www.abc.com via WAN1 but all other destinations via WAN2, you would create 2 static routes: first, get the IP address for www.abc.com = 199.181.132.250 Route>Static>New destination:199.181.132.250/32 (/32 denotes a host, /24 or /16 a network) gateway: <WAN1 ISP router IP address> interface: WAN1 and secondly the default route destination: 0.0.0.0/0 gateway: (leave empty) interface: WAN2 That will do it.

Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
virenlad

Thanks for reply, i have 4 differnt ip for same site. do i have to insert 4 static route. also my internal ip is as i told u that 192.168.1.0/255.255.255.0 will i have to define filrewall policy for abve addr to go to wan2 do i have to keep administrative distance same for both wan1 & wan2 gateway kindly help
Labels
Top Kudoed Authors