Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tomasbond
New Contributor

VPN over second WAN connection

Hi! I already have a working setup where i have 2 WAN, one LAN and one DMZ set up. I have a VPN SSL Tunnel set up on WAN1. My situation is that my WAN1 is a 6mb connection and my WAN2 is a 50mb connection. VPN gets in via WAN1 connection. Users can login and work ok. So policy are set up ok. Now with new COVID protocols and many users working from home that 6mb connection isnt enougth. Trying to set up the VPN to listen on WAN2 but i cant get it to the Fortinet login (portmapping the public WAN2 ip and nothing listening on port 443).

 

Got one default route for WAN1. No default route for WAN2. Some computers gets internet from WAN1 and other computers get internet from WAN2 (through a proxy). Both cases have internet and can reach the internet with the correct configuration.

 

Is there a way to troubleshoot why i am not getting the login screen even if fortigate is teeling me that is listening on the interface?

1 Solution
Toshi_Esumi
SuperUser
SuperUser

The VPN access hits WAN2, then the FGT checks the return route and finds the default route goes toward WAN1, which is "asymmetric routing" then drops. You need to have the second default route (I recommend a static route) toward WAN2 but set "priority" value higher than the existing default route so that those VPN's return packets go toward wan2, while all other in->out traffic(sessions) still use the wan1 default route.

View solution in original post

2 REPLIES 2
Toshi_Esumi
SuperUser
SuperUser

The VPN access hits WAN2, then the FGT checks the return route and finds the default route goes toward WAN1, which is "asymmetric routing" then drops. You need to have the second default route (I recommend a static route) toward WAN2 but set "priority" value higher than the existing default route so that those VPN's return packets go toward wan2, while all other in->out traffic(sessions) still use the wan1 default route.

tomasbond

Thanks a lot. After posting here i tryied adding the default route and started working. Thanks again for the explanation!

Labels
Top Kudoed Authors