Dear Experts, At SD-WAN configuration, when manual mode is used, is "set
priority-members" of "config service" stronger than "set priority" of
"config members"?I tried several values and it seems to be such
thing.Also, how should we use the both, inc...
Hello Experts, I have an issue about site-to-site SD-WAN. Here is the
situation.There are 2 ipsec tunnels between 2 Fortigates.One tunnel
(called as X) is a simple ipsec tunnel.The other (called as Y) is a
ipsec aggregation tunnel which has 3 ipsec t...
Hello Experts, We have aaa.bbb.209.136/28 global IP address range by
provider. The connection is PPPoE.As wan1 IP address, aaa.bbb.209.142 is
set at unnumbered IP. At DMZ, aaa.bbb.209.137/28 is set.Everything works
at Fortigate 60E. Recently, we boug...
Hello Experts, Let us assume there is a SD-WAN aggregation with WAN-A
and WAN-B.Can we have a configuration so that only WAN-A is usedwhen
WAN-B bandwidth is less than a specific speed (eg. < 1Mbps)and WAN-B is
automatically taking out from the aggre...
Dear Experts, When IPsec VPN at IPsec aggregation with SD-WAN is down,
Trap fgTrapVpnTunDown(1.3.6.1.4.1.12356.101.2.0.302) is not
sent,although "VPN tunnel down" is enabled at SNMP events.For
information linkDown(2) of MIB 1.3.6.1.6.3.1.1.5 is sent....
Dear Experts, I increased the value of probe-timeout (from 500 to
1000ms) at health-check. It worked. (Y is seen as green.) My next
question is:Can we have the separate probe-configuration for each
tunnel?For example, 500ms interval and 500ms probe-t...
Dear pukalmu3, Thanks for your comments. MTUs in all cases are 1500.Only
difference would be latency (delay) between normal case and slow case, I
think.I am now looking for some related parameters. Still waiting
experts comments. Thanks in advance.
Hello, Thanks for your reply.I could not find
1.3.6.1.4.1.12356.101.12.2.2.1.20 at Trap data in captured data.Is
Get-Request necessary to get value of 1.3.6.1.4.1.12356.101.12.2.2.1.20
? Best regards,