question

firsthop avatar image
1 Like"
firsthop asked

How do I configure traffic to always go out via WAN1 in dual-WAN?

I have two WANs, wan1 and wan2. I want to always prefer sending out traffic on wan1, unless wan1 is down. What is the easiest way to configure that?

FortiOSSD-WAN
10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

1 Answer

·
logographer avatar image
1 Like"
logographer answered

SD-WAN will be the best way to accomplish this in a simple and effective way.


Using SD-WAN, you can define wan1 and wan2 as members/zones in your SD-WAN. By adding a lower cost to wan1, you can use the lowest-cost strategy to prefer traffic to go out wan1.

Assuming you only need very simple routing, you can define your gateway during your SD-WAN member configurations, and the gateways will be added to the routing table.

On the other hand, set up Performance SLAs so that you can measure the health of both WANs. Then apply it in a SD-WAN rule using lowest cost strategy. If the health of wan1 falls below threshold, then SD-WAN will stop forwarding traffic to wan1 and start forwarding to wan2.

There is a SD-WAN quick-start guide you can follow:

https://docs.fortinet.com/document/fortigate/6.4.8/administration-guide/889544/sd-wan-quick-start


Instead of balancing using the implicit rule, use the lowest cost strategy instead:

https://docs.fortinet.com/document/fortigate/6.4.8/administration-guide/342836/lowest-cost-sla-strategy

10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Write an Answer

Hint: Notify or tag a user in this post by typing @username.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Welcome to FortiAnswers

FortiAnswers is the space dedicated to FortiSASE and FortiOS questions and suggestions.

  • Please review the Community guidelines
  • If you are a moderator, please refer to the Moderation guidelines
  • If something in the above guidelines is unclear, please post your question to the Community Feedback space or the Moderators' space