FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
tino_p
Staff
Staff
Article Id 299685
Description

This article describes the issue of SDWAN performance SLA being down due to DNS problems. This can happen especially when using Ping (to a domain name) as the protocol in Performance SLA.

 

For example:

 

1.PNG

In the Firewall's CLI, it also cannot ping to domain name: google.com. It usually indicates that the Firewall has an issue with DNS settings.

 

2.PNG
Scope SD-WAN, FortiGate, DNS.
Solution

To fix the problem, it is possible to either:

 

  1. Create a new Performance SLA - ping protocol, using the IP address instead of the domain name, and apply it in the SD-WAN rule.

3.PNG

Or,

 

  1. To fix the DNS issue on the Firewall, so that the Firewall can resolve the domain name to the IP address.

    4.PNG

    5.PNG