Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
gquerenghi
New Contributor

routing incoming traffic through different wan

I have a Fortigate60C with 2 internet connections connected to wan1 and wan2 I set up 2 dns servers and set the virtual ip' s each on one of the two wan public ip' s so basically my setup is this wan1 interface: 10.10.10.3 wan2 interface: 20.20.20.3 dns1: dmz 192.168.1.10 dns2: dmz 192.168.1.20 vip-dns1: 10.10.10.10 -> 192.168.1.10 vip-dns2: 20.20.20.20 -> 192.168.1.20 router connected to wan1: 10.10.10.2 router connected to wan2: 20.20.20.2 I configured the firewall policies and the static routes. The static routes are as follow 0.0.0.0 - GW 10.10.10.2 - destination wan1 - distance 5 0.0.0.0 - GW 20.20.20.2 - destination wan2 - distance 10 10.10.10.1 (isp network) - GW 10.10.10.3 - dest wan1 20.20.20.1 - GW 20.20.20.3 - dest wan2 My problem is that I cannot ping dns2 from the internet, however is I put the routes at the same distance I can ping it just fine. The problem is that some other servers with public vip from the wan2 cannot be accessed, from what my understanding because incoming packets are routed through the wan1 interface How should I configure my FG so dns1 gets accessed from wan1 and dns2 and all the othere servers from wan2? could it be that the problem is that I have to configure route priority instead of distance? thanks
0 REPLIES 0
Labels
Top Kudoed Authors