Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
john5
New Contributor

fortigate wan1 interface with sd-wan overlay a single vpn tunnel

Hello,

I have a test lab set up which will be going into production.  I have only 1 ISP circuit and that connects into each fortigate wan1 interface.  I created an IPSec tunnel between both fortigate 61f over the Internet.  In the future I plan to add 2 more vpn tunnels onto this single wan1 interface.  Today, I put the vpn tunnel interface as a single member of a single sd-wan zone.  I did not apply any sd-wan rules nor SLAs to this sd-wan on either  fortigates.  The vpn tunnel and sdwan are up.

I have one laptop set up behind each fortigate.  The local and remote LAN laptops can communicate with each other from their respective encryption domains.  However, neither laptop can access the Internet.  Firewall policies are set up for the VPN traffic.  I also set up the firewall policy default route to go to the Internet, with the next hop gateway pointing the SDWAN, also tried pointing to wan1 interface, and neither rule worked from laptop to the Internet.  What do the I need to do fix it?

 

laptop <--> fortiswitch<-->fortigate 61F<---cisco switch (3 vlans)--->fortigate 61F<-->fortiswitch<-->laptop

 

cisco switch port 2 vlan2 goes to left side fortigate, port 3 vlan3 connects to right side fortigate, port 4 goes to Internet, ip routing is enabled on switch for inter-vlan routing.

1 REPLY 1
amrit
Staff
Staff

Please make sure that you create two zones on the sd-wan zone page.

1. Virtual wan zone - for the Internet traffic

2.VPN Zone - for the IPsec traffic

Static default route for the sd-wan internet zone 0.0.0.0

Static route for the sd-wan Ipsec zone with specific destinations

Create sdwan rule for the VPN zone you can choose manual strategy -- priority IPsec tunnel

Add another sdwan rule for the internet traffic and this rule should be below the vpn  rule

if you don't create these rules, the traffic will be load-balanced between all sdwan zones due to the implicit rule. This may create routing issues 

 

Two firewall policies one for the internet sdwan zone and the other for the VPN zone

I

Amritpal Singh
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors