Hot!WAN Failover Best Practice - New Failover Connection

Author
kknuckles
New Member
  • Total Posts : 7
  • Scores: 0
  • Reward points: 0
  • Joined: 2016/02/29 15:56:02
  • Location: Pearl, MS
  • Status: offline
2017/03/20 12:47:51 (permalink) 5.4
0

WAN Failover Best Practice - New Failover Connection

I have a FG200D and we are getting ready to receive a new Cradlepoint 3G/4G router for failover of the main office only. The plan is to connect it to WAN2. My question is this: Would it be better to use WAN LLB and set a sky high priority like 99 for WAN1 and 1 for WAN2, or would it be better to use two static routes and weight them accordingly?
 
I mainly want to make sure WAN2 isn't going to be used unless WAN1 is absolutely down. I don't mind a small amount of traffic for health check but we are only allotted so much data per month on the fail over service without overage charges.
 
I've seen multiple posts about this and read multiple articles, but couldn't really determine the best method from those. I've only known FortiOS 5.4, which apparently isn't the favorite for this setup since most of the failover documentation still references 5.2.
 
Opinions and thoughts welcomed and thanks in advance.
 
Kevin
#1

2 Replies Related Threads

    MikePruett
    Platinum Member
    • Total Posts : 561
    • Scores: 4
    • Reward points: 0
    • Joined: 2014/01/08 19:39:40
    • Location: Montgomery, Al
    • Status: online
    Re: WAN Failover Best Practice - New Failover Connection 2017/03/20 13:14:01 (permalink)
    0
    I, personally, would do this.
     
    create a zone titled OUTSIDE
     
    place primary internet provider and secondary internet provider in there.
     
    Create two default routes, one to the primary and one to the secondary. Make the secondary have a slightly higher "priority" which in FortiOS just means cost.
     
    Configure link health monitoring through CLI for each connection. If primary WAN fails the configured number of times then it will yank the route and use the backup line.
     
    below is how to configure the link monitor
     
    config system link-monitor
    edit "wan1fail"
    set srcintf "wan1"
    set server "8.8.8.8"
    set interval 3
    set failtime 10
    set recoverytime 10
    set update-cascade-interface disable
    set protocol ping
    next
    end

    Mike Pruett
    Fortinet GURU
    #2
    kknuckles
    New Member
    • Total Posts : 7
    • Scores: 0
    • Reward points: 0
    • Joined: 2016/02/29 15:56:02
    • Location: Pearl, MS
    • Status: offline
    Re: WAN Failover Best Practice - New Failover Connection 2017/03/20 14:02:49 (permalink)
    0
    Thanks Mike!
    #3
    Jump to:
    © 2017 APG vNext Commercial Version 5.5