Hello. Please help in solving my problem.
So, I have 2 FGT devices.
Between devices constructed VPN tunnel (site to site).
If WAN1(on FGT100D) is fals , active route is reconstructed through WAN2 and 192.168.50.110 again becomes available.
That' s fine, but there was task of all traffic from network 192.168.50.0 pass back into vpn tunnel.
For this I used the policy routs.
Create a policy - and all work fine. Created a policy-and everything works-all requests to 192.168.50.110 go to FGT100D and then to the external network. But now no longer reconstructed route in case of failure on the WAN1 FGT100D.
That is, if WAN1 is not available - traffic is not redirected to WAN2.
Even if I create one more policy rout.
Please tell me how can I save resiliency fall WAN1 and implement wrapping all traffic back to FGT100D?
Here are the settings of my equipment.
Network diagram:
Configuring interfaces FGT100D:
Table of static routes 100D:
FW Policy 100d:
VPN tunnel 1 on the 100D:
VPN tunnel 2 on the 100D:
Configuring interfaces FGT80C:
static routes:
Policy routes 80C:
FW Policy 80C
VPN tunnel 1 on the 80C:
VPN tunnel 2 on the 80C: