Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sterling-BF
New Contributor

Setup WAN Failover w/ SDWAN with no downtime

We have a Fortigate 100F with WAN1 only. We are getting a secondary connection setup and want to setup to failover in case WAN1 goes down. My question is, is there a way to setup WAN failover without creating any downtime? If so, what is the best way to do so? If we setup SDWAN and add WAN1 and WAN2 as members, will it create downtime until we create the correct policies for SDWAN? Any suggestions/recommendations are appreciated!

3 REPLIES 3
dbu
Staff
Staff

Hi @Sterling-BF ,

 

Have a look here it may help with your configuration : 

https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/889544/sd-wan-quick-start

Regards!
If you have found a solution, please like and accept it to make it easily accessible for others.
akushwaha
Staff
Staff

Hi@Sterling-BF,

To configure SD-WAN the Port should not be part of any configuration on firewall, you would need to remove all the references of the port.

You can also achieve the redundancy without configuring the SD-WAN, please refer to below article:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Redundant-Internet-connection-without-load...

https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/360563/dual-internet-connect...

Regards,
Abhimanyu






 

xshkurti
Staff
Staff

@Sterling-BF 

You should consider:

1. First configure SDWAN zone and add backup line as a member. (lets say zone1)
2. Configure firewall policies and all other settings the same way you have for wan1

3. Configure static routing the same way you have for wan1 but with lower priority

4. After everything is configured the same (duplicate) change routing priority of sdwan and route all traffic through sdwan zone1.

5 You will not notice traffic rerouted. 

6. Start cleaning everything where you have configured wan1

7. Add wan1 in sdwan zone (note that if that is not removed from all settings, you can not add it)

8. Create sdwan rule to use wan1 as primary interface.

 

Hope this helps.

Do not forget to do more research on each step.
.

Labels
Top Kudoed Authors