Hi, im migrating a site from cisco to fortinet (FG-80f), and one thing the cisco provider couldnt do was creating multiple failover vpns in case the MPLS link went down.
the MPLS is connecting 6 locations, with differents internal ips (e.g : each site has 10.x.0.0/16). All is routed by static routes configured in every site. 10.0.0.0 /8 is being routed by MPLS. What I want to do is that when the mpls link of a site goes down, the VPN starts routing that network. I was thinking of using de sdwan for this, and making a simple redundant WAN conection by static routes. Whats the best way to achieve this?
thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
1) For SD-WAN to consider, all links are supposed to terminate on Fortigate(s) , is it the case, or there is a MPLS router of a sort?
2) The next question is - how do you plan on detecting MPLS link failure ?
we have a ISP MPLS router, and our FG, wich is part of the mpls network.
was thinking of doing SDWAN link health checks to monitor MPLS link failure
Thats what SDWAN on Fortigate is made for. You can combine any type of Interface to a logical SDWAN Interface. Assuming you are famliar with SDWAN you should try to combine your MPLS interface with your IPSec Interface and configure the WAN Link failover by using health checks, so something like this...
https://docs.fortinet.com/document/fortigate/6.4.7/administration-guide/580649/link-health-monitor
FCNSA 5, FCNSP 5, NSE 4
yeah, this is what i was thinking of doing. Wanted to know if i was forgetting some other method . thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1720 | |
1093 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.