Hello,
I have a test lab set up which will be going into production. I have only 1 ISP circuit and that connects into each fortigate wan1 interface. I created an IPSec tunnel between both fortigate 61f over the Internet. In the future I plan to add 2 more vpn tunnels onto this single wan1 interface. Today, I put the vpn tunnel interface as a single member of a single sd-wan zone. I did not apply any sd-wan rules nor SLAs to this sd-wan on either fortigates. The vpn tunnel and sdwan are up.
I have one laptop set up behind each fortigate. The local and remote LAN laptops can communicate with each other from their respective encryption domains. However, neither laptop can access the Internet. Firewall policies are set up for the VPN traffic. I also set up the firewall policy default route to go to the Internet, with the next hop gateway pointing the SDWAN, also tried pointing to wan1 interface, and neither rule worked from laptop to the Internet. What do the I need to do fix it?
laptop <--> fortiswitch<-->fortigate 61F<---cisco switch (3 vlans)--->fortigate 61F<-->fortiswitch<-->laptop
cisco switch port 2 vlan2 goes to left side fortigate, port 3 vlan3 connects to right side fortigate, port 4 goes to Internet, ip routing is enabled on switch for inter-vlan routing.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Please make sure that you create two zones on the sd-wan zone page.
1. Virtual wan zone - for the Internet traffic
2.VPN Zone - for the IPsec traffic
Static default route for the sd-wan internet zone 0.0.0.0
Static route for the sd-wan Ipsec zone with specific destinations
Create sdwan rule for the VPN zone you can choose manual strategy -- priority IPsec tunnel
Add another sdwan rule for the internet traffic and this rule should be below the vpn rule
if you don't create these rules, the traffic will be load-balanced between all sdwan zones due to the implicit rule. This may create routing issues
Two firewall policies one for the internet sdwan zone and the other for the VPN zone
I
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1665 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.