Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
esteve
New Contributor

Wan Link Load Balanced + Traffic Shaping

Hello;

 

I've been in this forum lots of times and I resolved many doubts about Fortigate stuff, but since some days ago I'm in trouble with a specific thing I can't seem to find a solution in internet.

 

We have a Fortigate 100E with FortiOS 5.4.8, and everything is running nicely in our office. I have set up a lot of stuff with your help and I'm very happy because I've learnt a lot. The problem I'm facing is that I don't seem to be able to apply a Traffic Shaper Policy to a single interface which is part of a Wan-Link Load Balance interface.

 

I explain the situation:

 

We have 7 internet lines, 5 for Internet (4x FTTH through PPPoE + 1x 4G LTE through WAN) and 2 for VoIP (1x MacroLAN through WAN + 1x FTTH through PPPoE). I've set up the VoIP lines to jump over if any of them fail, a simple failover thing, and the 5 lines for internet are members of the Wan-Link Load Balance interface.

 

Now the issue: I need to setup two traffic shapers among the members of the Wan-Link Load Balance interface, one for the FTTH lines and other for the 4G LTE line, but it does not allow me to do it. Since the FTTH lines are 300Mb and the 4G LTE line is 50Mb, I need to lower the traffic shaper for the 4G LTE line in case the FTTH lines are out.

 

My other concern is that, if I configure the 4G LTE line outside the Wan-Link Load Balance interface, if all the FTTH members go down, it would jump to the 4G LTE line automatically? because maybe that's the only way to accomplish it?

 

I hope to have explained it well.

 

Thank you!

2 REPLIES 2
ericli_FTNT
Staff
Staff

You could configure WAN LLB algorithm among members by this way. Shaping policy can only be applied on WAN

 

esteve

Ya, I've thought about that, but I can't. I forgot to mention that the Wan LLB should be configured with the session algorithm, since the activity at the office requires to control sessions instead of bandwidth. We have like 100 computers, and all together don't consume more than 100-150Mbit/s of bandwidth, but since workers open a lot of stuff at once every PC ends having like 80-100 sessions. Of course, the problem isn't the Fortigate, the CPU idles at 95-97%, the problem are the end ISP routers. They seem to have a session limit or something per line because I've tried to disconnect all FTTH lines but one and internet gets damn slow, even if the bandwidth consumption is 20-30% of the total bandwidth capacity of the FTTH. A minimum of 2 out of 4 FTTH's must be working in order to have internet speed as it should be. I've talked with them but they claim there's no such limit, which is obviously a lie.

 

In addition, the change of the algorithm would not change the traffic shape, and if only the 4G LTE line is up the traffic shape policy would be applied as normal, which is higher for FTTH than for 4G LTE.

 

What is your suggestion? would it work if I remove the 4G LTE from the Wan LLB and I create a static route + a separate traffic shape policy for it?, because in fact, if any member in the Wan LLB is up the Fortigate should remove the Wan LLB static route and the 4G LTE one should start working...maybe :(

 

Thanks for the help! :)

Labels
Top Kudoed Authors